VDB

CVE-2019-0863

CVE-2019-0863 PUBLISHED KEV CVSS 7.199999809265137 HIGH

An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it.To exploit the vulnerability, in a local attack scenario, an attacker could run a specially crafted application to elevate the attacker's privilege level, aka 'Windows NDIS Elevation of Privilege Vulnerability'.

EPSS 6.16% · 91.0th percentile

Risk Scores

CVSS 2.0
7.199999809265137
EPSS Score
6.16%
91.0th percentile

Affected Products

VendorProductVersions
MicrosoftWindows Server2012, 2019, version 1803 (Core Installation)
MicrosoftWindows 10 Version 1903 for ARM64-based Systemsunspecified, unspecified
microsoftwindows_7
microsoftwindows_10_1709
microsoftwindows_10_1703
microsoftwindows_server_2008r2, r2, r2
microsoftwindows_10_1507
microsoftwindows_server_2019
MicrosoftWindows Server, version 1903 (Server Core installation)unspecified, unspecified
MicrosoftWindows 10 Version 1903 for 32-bit Systemsunspecified, unspecified
microsoftwindows_10_1903
microsoftwindows_server_2012r2, *, r2
microsoftwindows_server_1903
microsoftwindows_server_2016
microsoftwindows_10_1803
MicrosoftWindows10 Version 1809 for 32-bit Systems, 10 Version 1803 for ARM64-based Systems, 10 Version 1803 for x64-based Systems
microsoftwindows_10_1809
microsoftwindows_rt_8.1
microsoftwindows_10_1607
MicrosoftWindows 10 Version 1903 for x64-based Systemsunspecified, unspecified

…and 2 more

Timeline

  • May 14, 2019 VulnCheck KEV Exploitation
  • May 15, 2019 CVE Published
  • May 15, 2019 PoC Published
  • May 24, 2019 PoC Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Nov 3, 2021 CISA KEV Added
  • Nov 8, 2021 PoC Published
  • Nov 20, 2021 PoC Published
  • Dec 27, 2021 EPSS Score
  • Feb 28, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›