CVE-2019-0863 PUBLISHED KEV CVSS 7.199999809265137 HIGH

An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it.To exploit the vulnerability, in a local attack scenario, an attacker could run a specially crafted application to elevate the attacker's privilege level, aka 'Windows NDIS Elevation of Privilege Vulnerability'.

EPSS 6.39% · 90.9th percentile

Risk Scores

CVSS v2.0
7.199999809265137
EPSS Score
6.39%
90.9th percentile

Affected Products

VendorProductVersions
MicrosoftWindows Server2008 R2 for Itanium-Based Systems Service Pack 1, 2012, 2019 (Core installation)
MicrosoftWindows 10 Version 1903 for ARM64-based Systemsunspecified, unspecified
microsoftwindows_7
microsoftwindows_10_1709
microsoftwindows_10_1703
microsoftwindows_server_2008r2, r2, r2
microsoftwindows_10_1507
microsoftwindows_server_2019
MicrosoftWindows Server, version 1903 (Server Core installation)unspecified, unspecified
MicrosoftWindows 10 Version 1903 for 32-bit Systemsunspecified, unspecified
microsoftwindows_10_1903
microsoftwindows_server_2012r2, r2, r2
microsoftwindows_server_1903
microsoftwindows_server_2016
microsoftwindows_10_1803
MicrosoftWindows10 Version 1607 for x64-based Systems, 10 Version 1607 for 32-bit Systems, 10 for x64-based Systems
microsoftwindows_10_1809
microsoftwindows_rt_8.1
microsoftwindows_10_1607
MicrosoftWindows 10 Version 1903 for x64-based Systemsunspecified, unspecified

…and 2 more

Timeline

References

Open in Interactive Console →