CVE-2019-1025
Last modified
CVE-2019-1025 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application or to convince a user to open a specific file on a network share. EPSS estimates a 5.39% chance of exploitation in the next 30 days.
Description
A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application or to convince a user to open a specific file on a network share. The vulnerability would not allow an attacker to execute code or to elevate user rights directly, but it could be used to cause a target system to stop responding. The update addresses the vulnerability by correcting how Windows handles objects in memory.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Windows 10 | All versions | — |
| Microsoft | Windows 10 | 1607 | — |
| Microsoft | Windows 10 | 1703 | — |
| Microsoft | Windows 10 | 1709 | — |
| Microsoft | Windows 10 | 1803 | — |
| Microsoft | Windows 10 | 1809 | — |
| Microsoft | Windows 10 | 1903 | — |
| Microsoft | Windows 7 | All versions | Sp1 |
| Microsoft | Windows 8.1 | All versions | — |
| Microsoft | Windows Rt 8.1 | All versions | — |
| Microsoft | Windows Server 2008 | All versions | Sp2 |
| Microsoft | Windows Server 2008 | r2 | Sp1 |
| Microsoft | Windows Server 2012 | All versions | — |
| Microsoft | Windows Server 2012 | r2 | — |
| Microsoft | Windows Server 2016 | All versions | — |
| Microsoft | Windows Server 2016 | 1803 | — |
| Microsoft | Windows Server 2016 | 1903 | — |
| Microsoft | Windows Server 2019 | All versions | — |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-1025?
How severe is CVE-2019-1025?
How do I fix CVE-2019-1025?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-10244In Eclipse Kura versions up to 4.0.0, the Web UI package and…
- CVE-2019-10245In Eclipse OpenJ9 prior to the 0.14.0 release, the Java byte…7.5
- CVE-2019-10246In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the ser…5.3
- CVE-2019-10247In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 …5.3
- CVE-2019-10248Eclipse Vorto versions prior to 0.11 resolved Maven build ar…
- CVE-2019-10249All Xtext & Xtend versions prior to 2.18.0 were built using …8.1
- CVE-2019-10250UCWeb UC Browser 7.0.185.1002 on Windows uses HTTP for downl…
- CVE-2019-10251The UCWeb UC Browser application through 2019-03-26 for Andr…
- CVE-2019-10253A Cross-Site Request Forgery (CSRF) vulnerability exists in …6.5
- CVE-2019-10254In MISP before 2.4.105, the app/View/Layouts/default.ctp def…
- CVE-2019-10255An Open Redirect vulnerability for all browsers in Jupyter N…
- CVE-2019-10256An authentication bypass vulnerability in VIVOTEK IPCam vers…9.8
Are you affected by CVE-2019-1025?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
