CVE Database
/

CVE-2019-0707

Back to search

CVE-2019-0707

Published: May 16, 2019

Modified: Aug 4, 2024

PUBLISHED

Description

An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it.To exploit the vulnerability, in a local attack scenario, an attacker could run a specially crafted application to elevate the attacker's privilege level, aka 'Windows NDIS Elevation of Privilege Vulnerability'.

VendorProductVersions

Microsoft

Windows Server

affected
2012
affected
2012 (Core installation)
affected
2012 R2
affected
2012 R2 (Core installation)
affected
2016

+4 more versions

Microsoft

Windows

affected
8.1 for 32-bit systems
affected
8.1 for x64-based systems
affected
RT 8.1
affected
10 for 32-bit Systems
affected
10 for x64-based Systems

+13 more versions

Microsoft

Windows 10 Version 1903 for 32-bit Systems

affected
unspecified

Microsoft

Windows 10 Version 1903 for x64-based Systems

affected
unspecified

Microsoft

Windows 10 Version 1903 for ARM64-based Systems

affected
unspecified

Microsoft

Windows Server, version 1903 (Server Core installation)

affected
unspecified

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now