Description
Multiple vulnerabilities were found in Microsoft Products (Extended Support Update). Malicious users can exploit these vulnerabilities to execute arbitrary code, obtain sensitive information, cause denial of service, spoof user interface, gain privileges.
Below is a complete list of vulnerabilities:
- A memory corruption vulnerability in Scripting Engine can be exploited remotely via specially crafted website to execute arbitrary code.
- An information disclosure vulnerability in Windows Graphics Component can be exploited remotely via specially crafted document to obtain sensitive information.
- A remote code execution vulnerability in Hyper-V can be exploited remotely via specially crafted application to execute arbitrary code.
- A denial of service vulnerability in Windows Hyper-V can be exploited remotely via specially crafted application to cause denial of service.
- A denial of service vulnerability in Windows can be exploited remotely via specially crafted application to cause denial of service.
- A remote code execution vulnerability in Microsoft Graphics can be exploited remotely via specially crafted embedded to execute arbitrary code.
- A security UI vulnerability in Bluetooth BR/EDR specification can be exploited remotely to spoof user interface.
- An elevation of privilege vulnerability in Windows can be exploited remotely via specially crafted application to gain privileges.
- An information disclosure vulnerability in Microsoft Graphics Component can be exploited remotely via specially crafted application to obtain sensitive information.
- A remote code execution vulnerability in Jet Database Engine can be exploited remotely via specially crafted file to execute arbitrary code.
- An elevation of privilege vulnerability in Win32k can be exploited remotely via specially crafted application to gain privileges.
- A denial of service vulnerability in XmlLite Runtime can be exploited remotely via specially crafted requests to cause denial of service.
- A remote code execution vulnerability in Windows DHCP Server can be exploited remotely via specially crafted packets to execute arbitrary code.
- An elevation of privilege vulnerability in Windows Kernel can be exploited remotely via specially crafted application to gain privileges.
- A denial of service vulnerability in Windows DHCP Server can be exploited remotely via specially crafted packets to cause denial of service.
- An elevation of privilege vulnerability in Windows ALPC can be exploited remotely via specially crafted application to gain privileges.
- An information disclosure vulnerability in Windows Kernel can be exploited remotely via specially crafted application to obtain sensitive information.
- A remote code execution vulnerability in MS XML can be exploited remotely via specially crafted website to execute arbitrary code.
- A remote code execution vulnerability in Windows DHCP Client can be exploited remotely via specially crafted to execute arbitrary code.
- An elevation of privilege vulnerability in Microsoft Windows p2pimsvc can be exploited remotely via specially crafted application to gain privileges.
- A remote code execution vulnerability in Remote Desktop Services can be exploited remotely via specially crafted packets to execute arbitrary code.
Original advisories
- CVE-2019-1133
- CVE-2019-1143
- CVE-2019-0720
- CVE-2019-0715
- CVE-2019-0716
- CVE-2019-1144
- CVE-2019-9506
- CVE-2019-1154
- CVE-2019-1177
- CVE-2019-1153
- CVE-2019-1147
- CVE-2019-1078
- CVE-2019-0714
- CVE-2019-1169
- CVE-2019-1145
- CVE-2019-1187
- CVE-2019-1151
- CVE-2019-1146
- CVE-2019-1148
- CVE-2019-1178
- CVE-2019-1157
- CVE-2019-1213
- CVE-2019-1155
- CVE-2019-0723
- CVE-2019-1149
- CVE-2019-1159
- CVE-2019-1212
- CVE-2019-1162
- CVE-2019-1150
- CVE-2019-1164
- CVE-2019-1152
- CVE-2019-1158
- CVE-2019-1156
- CVE-2019-1228
- CVE-2019-1057
- CVE-2019-0736
- CVE-2019-1168
- CVE-2019-1206
- CVE-2019-0718
- CVE-2019-1172
- CVE-2019-1182
- CVE-2019-1181
- CVE-2019-1180
- ADV190023
Exploitation
Public exploits exist for this vulnerability.
Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.
Related products
- Microsoft-Internet-Explorer
- Microsoft-Windows
- Microsoft-Windows-Server
- Microsoft-Windows-Server-2012
- Microsoft-Windows-7
- Microsoft-Windows-Server-2008
CVE list
- CVE-2019-1194 critical
- CVE-2019-1133 critical
- CVE-2019-1143 high
- CVE-2019-0720 critical
- CVE-2019-0715 high
- CVE-2019-0716 warning
- CVE-2019-1144 critical
- CVE-2019-9506 critical
- CVE-2019-1154 high
- CVE-2019-1177 critical
- CVE-2019-1153 high
- CVE-2019-1147 critical
- CVE-2019-1078 high
- CVE-2019-0714 high
- CVE-2019-1169 critical
- CVE-2019-1145 critical
- CVE-2019-1187 critical
- CVE-2019-1151 critical
- CVE-2019-1146 critical
- CVE-2019-1148 high
- CVE-2019-1178 critical
- CVE-2019-1180 critical
- CVE-2019-1181 critical
- CVE-2019-1157 critical
- CVE-2019-1213 critical
- CVE-2019-0718 high
- CVE-2019-1172 warning
- CVE-2019-1155 critical
- CVE-2019-0723 high
- CVE-2019-1149 critical
- CVE-2019-1206 critical
- CVE-2019-1159 critical
- CVE-2019-1212 critical
- CVE-2019-1162 critical
- CVE-2019-1150 critical
- CVE-2019-1164 critical
- CVE-2019-1152 critical
- CVE-2019-1158 high
- CVE-2019-1156 critical
- CVE-2019-1228 high
- CVE-2019-1182 critical
- CVE-2019-1057 critical
- CVE-2019-0736 critical
- CVE-2019-1168 critical
KB list
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com
Found an inaccuracy in the description of this vulnerability? Let us know!