7
CVE-2019-0707
- EPSS 0.95%
- Veröffentlicht 16.05.2019 19:29:00
- Zuletzt bearbeitet 21.11.2024 04:17:08
- Erkennungen
An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it.To exploit the vulnerability, in a local attack scenario, an attacker could run a specially crafted application to elevate the attacker's privilege level, aka 'Windows NDIS Elevation of Privilege Vulnerability'.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 10 Version -
Microsoft ≫ Windows 10 Version 1607
Microsoft ≫ Windows 10 Version 1703
Microsoft ≫ Windows 10 Version 1709
Microsoft ≫ Windows 10 Version 1803
Microsoft ≫ Windows 10 Version 1809
Microsoft ≫ Windows 10 Version 1903
Microsoft ≫ Windows 8.1 Version -
Microsoft ≫ Windows Rt 8.1 Version -
Microsoft ≫ Windows Server 2012 Version -
Microsoft ≫ Windows Server 2012 Version r2
Microsoft ≫ Windows Server 2016 Version -
Microsoft ≫ Windows Server 2016 Version 1803
Microsoft ≫ Windows Server 2016 Version 1903
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.95% | 0.565 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7 | 1 | 5.9 |
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 6.9 | 3.4 | 10 |
AV:L/AC:M/Au:N/C:C/I:C/A:C
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0707