← Back

CVE-2019-1007

nvd nist
Published: Jun 12, 2019Modified: May 20, 2025

JSON object

Loading...
7.8
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD (Secondary)

Description

An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that could exploit the vulnerability. This vulnerability by itself does not allow arbitrary code to be run. However, this vulnerability could be used in conjunction with one or more vulnerabilities (e.g. a remote code execution vulnerability and another elevation of privilege) that could take advantage of the elevated privileges when running. The update addresses the vulnerability by correcting how the Windows Audio Service handles processes these requests.

Affected (11)

3 products
Windows 10
Windows Server 2016
Windows Server 2019
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
All versions
Version 1607
Version 1703
Version 1709
Version 1803
Version 1809
Version 1903
Microsoft
All versions
Version 1803
Version 1903
All versions

References (2)

Timeline

No history available yet.