First published: Tue Nov 12 2019(Updated: )
An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Information Disclosure Vulnerability'.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Open Enclave Software Development Kit | <=0.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1370 is classified as a moderate severity information disclosure vulnerability.
To fix CVE-2019-1370, update the Open Enclave SDK to version 0.8.0 or later.
CVE-2019-1370 affects Microsoft Open Enclave Software Development Kit versions up to 0.7.0.
CVE-2019-1370 has the potential for exploitation to expose sensitive information stored in memory.
CVE-2019-1370 was disclosed in 2019 as part of Microsoft security updates.