peter bassill · operator
$ cve CVE-2019-1148 JSON

CVE-2019-1148 EXPLOIT

5.5
MEDIUM · CVSS 3.1 · EPSS 2.8% (pctl 86)

Patch early

A public exploit exists.

Description

An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The update addresses the vulnerability by correcting the way in which the Windows Graphics Component handles objects in memory.

Scoring

CVSS5.5 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS2.83% — more likely to be exploited than 86% of all CVEs
WeaknessCWE-125
On CISA KEVno
Public exploityes
Published2019-08-14
Last modified2026-06-17

Affected (9)

VendorProduct
microsoftoffice
microsoftwindows 10
microsoftwindows 7
microsoftwindows 8.1
microsoftwindows rt 8.1
microsoftwindows server 2008
microsoftwindows server 2012
microsoftwindows server 2016
microsoftwindows server 2019

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD