CVE-2019-1227: Windows Kernel Information Disclosure Vulnerability
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1228.
Other sources
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would not allow an attacker to execute code or to elevate user rights directly, but it could be used to obtain information that could be used to try to further compromise the affected system. The update addresses the vulnerability by correcting how the Windows kernel handles objects in memory.
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must be able to log on to an affected Windows 10, Windows Server 2016, or Windows Server 2019 system and run a specially crafted application. The CVSS vector indicates local access and low privileges are required; no user interaction is required.
What is the impact if exploitation succeeds?
Successful exploitation discloses information that could help further compromise the system. The vulnerability does not directly permit code execution or elevation of user rights.
What should be done if affected systems cannot be patched immediately?
Limit logon access to affected systems and restrict the ability of low-privileged users to run untrusted or specially crafted applications. These measures address the required local, authenticated attack path.
How is the issue fixed?
A patch is available. The update corrects how the Windows kernel handles objects in memory.