peter bassill · operator
$ cve CVE-2019-1245 JSON

CVE-2019-1245 EXPLOIT

6.5
MEDIUM · CVSS 3.1 · EPSS 12.9% (pctl 96)

Patch early

A public exploit exists.

Description

An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'DirectWrite Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1244, CVE-2019-1251.

Scoring

CVSS6.5 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS12.89% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2019-09-11
Last modified2026-06-17

Affected (8)

VendorProduct
microsoftwindows 10
microsoftwindows 7
microsoftwindows 8.1
microsoftwindows rt 8.1
microsoftwindows server 2008
microsoftwindows server 2012
microsoftwindows server 2016
microsoftwindows server 2019

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD