CVE-2019-1019
A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages. To exploit this vulnerability, an attacker could send a specially crafted authentication request. An attacker who successfully exploited this vulnerability could access another machine using the original user privileges. The issue has been addressed by changing how NTLM validates network authentication messages.
- Affected products
- Windows
- Microsoft Windows 10
- All versions
- Microsoft Windows 7
- All versions
- Microsoft Windows 8.1
- All versions
- Microsoft Windows Rt 8.1
- All versions
- Microsoft Windows Server 2008
- All versions
- Microsoft Windows Server 2012
- All versions
- CVSS 3.0
- 8.5 HIGH
- EPSS
- 15.1% (96th percentile)
- Weakness
- CWE-200
- NVD status
- Modified
- Published
- 2019-06-12
CVE-2019-1019 at NVD
4 known exploits for CVE-2019-1019
Proof-of-concept code and exploit modules indexed by Sploitus
UltraRealy_with_CVE-2019-1040
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Microsoft
Microsoft Windows 10.0.17134.648 HTTP -> SMB NTLM Reflection Leads to Privilege Elevation Exploit
Microsoft Windows 10.0.17134.648 - HTTP -> SMB NTLM Reflection Leads to Privilege Elevation