← Back

CVE-2019-0959

nvd nist
Published: Jun 12, 2019Modified: May 20, 2025

JSON object

Loading...
7.8
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD (Secondary)

Description

An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted application to take control over the affected system. The security update addresses the vulnerability by correcting how CLFS handles objects in memory.

Affected (6)

3 products
Windows 10
Windows Server 2016
Windows Server 2019
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 1803
Version 1809
Version 1903
Microsoft
Version 1803
Version 1903
All versions

References (2)

Timeline

No history available yet.