Sploitus

CVE-2019-1040

12 known exploits for CVE-2019-1040

A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection. An attacker who successfully exploited this vulnerability could gain the ability to downgrade NTLM security features. To exploit this vulnerability, the attacker would need to tamper with the NTLM exchange. The attacker could then modify flags of the NTLM packet without invalidating the signature. The update addresses the vulnerability by hardening NTLM MIC protection on the server-side.

Affected products
Windows
Microsoft Windows 10
All versions
Microsoft Windows 7
All versions
Microsoft Windows 8.1
All versions
Microsoft Windows Rt 8.1
All versions
Microsoft Windows Server 2008
All versions
Microsoft Windows Server 2012
All versions
CVSS 3.0
5.9 MEDIUM
EPSS
48.0% (99th percentile)
NVD status
Modified
Published
2019-06-12
CVE-2019-1040 at NVD
Authoritative description, scoring and affected products

12 known exploits for CVE-2019-1040

Proof-of-concept code and exploit modules indexed by Sploitus