{"containers":{"cna":{"title":"Windows Kernel Information Disclosure Vulnerability","datePublic":"2019-08-13T07:00:00.000Z","affected":[{"vendor":"Microsoft","product":"Windows 7","cpes":["cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:x86:*"],"platforms":["32-bit Systems"],"versions":[{"version":"6.1.0","lessThan":"publication","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows 7 Service Pack 1","cpes":["cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:x64:*"],"platforms":["x64-based Systems"],"versions":[{"version":"6.1.0","lessThan":"publication","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2008 Service Pack 2","cpes":["cpe:2.3:o:microsoft:windows_server_2008_sp2:*:*:*:*:*:*:x64:*","cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:itanium:*"],"platforms":["32-bit Systems","IA64-based Systems"],"versions":[{"version":"6.0.0","lessThan":"publication","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2008 Service Pack 2 (Server Core installation)","cpes":["cpe:2.3:o:microsoft:windows_server_2008_sp2:*:*:*:*:*:*:x64:*","cpe:2.3:o:microsoft:windows_server_2008_sp2:*:*:*:*:*:*:x86:*"],"platforms":["32-bit Systems","x64-based Systems"],"versions":[{"version":"6.0.0","lessThan":"publication","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2008  Service Pack 2","cpes":["cpe:2.3:o:microsoft:windows_server_2008_sp2:*:*:*:*:*:*:x86:*"],"platforms":["x64-based Systems"],"versions":[{"version":"6.0.0","lessThan":"publication","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2008 R2 Systems Service Pack 1","cpes":["cpe:2.3:o:microsoft:windows_server_2008_R2:*:*:*:*:*:*:itanium:*"],"platforms":["IA64-based Systems"],"versions":[{"version":"6.1.0","lessThan":"publication","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2008 R2 Service Pack 1","cpes":["cpe:2.3:o:microsoft:windows_server_2008_R2:*:*:*:*:*:*:x64:*"],"platforms":["x64-based Systems"],"versions":[{"version":"6.1.0","lessThan":"publication","versionType":"custom","status":"affected"}]},{"vendor":"Microsoft","product":"Windows Server 2008 R2 Service Pack 1 (Server Core installation)","cpes":["cpe:2.3:o:microsoft:windows_server_2008_R2:*:*:*:*:*:*:x64:*"],"platforms":["x64-based Systems"],"versions":[{"version":"6.0.0","lessThan":"publication","versionType":"custom","status":"affected"}]}],"descriptions":[{"value":"An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.\nTo exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would not allow an attacker to execute code or to elevate user rights directly, but it could be used to obtain information that could be used to try to further compromise the affected system.\nThe update addresses the vulnerability by correcting how the Windows kernel handles objects in memory.","lang":"en-US"}],"problemTypes":[{"descriptions":[{"description":"Information Disclosure","lang":"en-US","type":"Impact"}]}],"providerMetadata":{"orgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","shortName":"microsoft","dateUpdated":"2024-05-29T16:51:13.141Z"},"references":[{"tags":["x_refsource_MISC"],"url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1228"}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en-US","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","baseSeverity":"MEDIUM","baseScore":5.5,"vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C"}}]},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-200","lang":"en","description":"CWE-200 Exposure of Sensitive Information to an Unauthorized Actor"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-06-05T14:06:10.821902Z","id":"CVE-2019-1228","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-06-05T14:06:24.765Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-04T18:13:29.252Z"},"title":"CVE Program Container","references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1228"}]}]},"cveMetadata":{"assignerOrgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","assignerShortName":"microsoft","cveId":"CVE-2019-1228","datePublished":"2019-08-14T20:55:06.000Z","dateReserved":"2018-11-26T00:00:00.000Z","dateUpdated":"2024-08-04T18:13:29.252Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}