Vulnerabilities > CVE-2019-1255 - Unspecified vulnerability in Microsoft products

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
microsoft
nessus

Summary

A denial of service vulnerability exists when Microsoft Defender improperly handles files, aka 'Microsoft Defender Denial of Service Vulnerability'.

Nessus

NASL familyWindows
NASL idMICROSOFT_MALWARE_PROTECTION_ENGINE_1_1_16400_2.NASL
descriptionAn elevation of privilege vulnerability exists in Microsoft Malware Protection Engine due to improper file handling. An authenticated, remote attacker can exploit this, to gain elevated privileges.
last seen2020-06-01
modified2020-06-02
plugin id130091
published2019-10-21
reporterThis script is Copyright (C) 2019 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/130091
titleMicrosoft Malware Protection Engine Elevation of Privilege Vulnerability

The Hacker News

idTHN:AB828E4EB75F9C7BC37B672D9FD0092E
last seen2019-09-24
modified2019-09-24
published2019-09-24
reporterThe Hacker News
sourcehttps://thehackernews.com/2019/09/windows-update-zero-day.html
titleMicrosoft Releases Emergency Patches for IE 0-Day and Windows Defender Flaw