CVE-2019-1153
Microsoft グラフィックス コンポーネントの情報漏えいの脆弱性
- 公開済み
- 2019/08/14
- 更新済み
- 2024/08/04
- CNA の割り当て
- microsoft
- 観察された証拠
- 2019/08/15
プライマリ CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N低 · 今後 30 日間
- パーセンタイル
- 85.9%
- モデルの日付
- 2026/09/21
EPSS は統計的な推定値であり、確実性や影響の尺度ではありません。 CVSS、KEV ステータス、暴露、環境と組み合わせます。
概要
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The update addresses the vulnerability by correcting the way in which the Windows Graphics Component handles objects in memory. Microsoft Windows グラフィックス コンポーネントがメモリ内のオブジェクトを不適切に処理する際に、情報漏えいの脆弱性が存在します。この脆弱性の悪用に成功した攻撃者は、情報を取得してユーザーのシステムをさらに侵害する可能性があります。この脆弱性を悪用するには、攻撃者は影響を受けるシステムにログオンし、特別に細工されたアプリケーションを実行する必要があります。この更新プログラムは、Windows グラフィックス コンポーネントがメモリ内のオブジェクトを処理する方法を修正することにより、この脆弱性に対処します。
ソース
1Google Security Research · windows · 2019/08/15
責任ある使用
脆弱性情報は、自分が所有しているシステム、またはテストを許可されているシステムでのみ使用してください。 Kitploit は公開研究メタデータにリンクしており、エクスプロイト コードや悪意のあるペイロードは保存しません。