Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2019-1255

Quick assessment

Affected
Microsoft Microsoft Security Essentials
Exploitation
High exploitation probability; assess promptly
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Microsoft Windows Defender是美国微软(Microsoft)公司的一套Windows系统附带的防病毒软件。 Microsoft Windows Defender中存在输入验证错误漏洞。攻击者可利用该漏洞造成拒绝服务。以下产品及版本受到影响:Microsoft Forefront Endpoint Protection 2010;Security Essentials;System Center 2012 Endpoint Protection,System Center 2012

AI Predicted 5.9 Difficulty: Easy EPSS 4.15% · P91

Possible ATT&CK Techniques 1 AI

T1027 · Obfuscated Files or Information
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2019-1255

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
A denial of service vulnerability exists when Microsoft Defender improperly handles files, aka 'Microsoft Defender Denial of Service Vulnerability'.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Microsoft Windows Defender 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Microsoft Windows Defender是美国微软(Microsoft)公司的一套Windows系统附带的防病毒软件。 Microsoft Windows Defender中存在输入验证错误漏洞。攻击者可利用该漏洞造成拒绝服务。以下产品及版本受到影响:Microsoft Forefront Endpoint Protection 2010;Security Essentials;System Center 2012 Endpoint Protection,System Center 2012
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Microsoft Microsoft Security Essentials unspecified -
Microsoft Microsoft System Center 2012 Endpoint Protection -
Microsoft Microsoft Forefront Endpoint Protection 2010 -
Microsoft Windows Defender on Windows 7 for 32-bit Systems Service Pack 1 -
Microsoft Windows Defender on Windows 7 for x64-based Systems Service Pack 1 -
Microsoft Windows Defender on Windows Server 2008 R2 for x64-based Systems (Server Core installation) Service Pack 1 -
Microsoft Windows Defender on Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1 -
Microsoft Windows Defender on Windows Server 2008 R2 for x64-based Systems Service Pack 1 -
Microsoft Windows Defender on Windows Server 2008 for 32-bit Systems (Server Core installation) Service Pack 2 -
Microsoft Windows Defender on Windows Server 2012 unspecified -
Microsoft Windows Defender on Windows Server 2012 (Server Core installation) unspecified -
Microsoft Windows Defender on Windows 8.1 for 32-bit systems unspecified -
Microsoft Windows Defender on Windows 8.1 for x64-based systems unspecified -
Microsoft Windows Defender on Windows Server 2012 R2 unspecified -
Microsoft Windows Defender on Windows RT 8.1 unspecified -
Microsoft Windows Defender on Windows Server 2012 R2 (Server Core installation) unspecified -
Microsoft Windows Defender on Windows 10 for 32-bit Systems unspecified -
Microsoft Windows Defender on Windows 10 for x64-based Systems unspecified -
Microsoft Windows Defender on Windows Server 2016 unspecified -
Microsoft Windows Defender on Windows 10 Version 1607 for 32-bit Systems unspecified -
Microsoft Windows Defender on Windows 10 Version 1607 for x64-based Systems unspecified -
Microsoft Windows Defender on Windows Server 2016 (Server Core installation) unspecified -
Microsoft Windows Defender on Windows 10 Version 1703 for 32-bit Systems unspecified -
Microsoft Windows Defender on Windows 10 Version 1703 for x64-based Systems unspecified -
Microsoft Windows Defender on Windows 10 Version 1709 for 32-bit Systems unspecified -
Microsoft Windows Defender on Windows 10 Version 1709 for x64-based Systems unspecified -
Microsoft Windows Defender on Windows 10 Version 1803 for 32-bit Systems unspecified -
Microsoft Windows Defender on Windows 10 Version 1803 for x64-based Systems unspecified -
Microsoft Windows Defender on Windows Server, version 1803 (Server Core Installation) unspecified -
Microsoft Windows Defender on Windows 10 Version 1803 for ARM64-based Systems unspecified -

II. Public POCs for CVE-2019-1255

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2019-1255

请登录查看更多情报信息。

Vendor Advisories for CVE-2019-1255 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2019-1255

No comments yet


Leave a comment