Microsoft Windows Win32k是美国微软(Microsoft)公司的一个用于Windows多用户管理的系统文件。 Microsoft win32k组件中存在安全漏洞,该漏洞源于程序无法正确处理内存中的对象。攻击者可通过运行特制的应用程序利用该漏洞在内核模式中运行任意代码。以下产品及版本受到影响:Microsoft Windows 10,Windows 10版本1607,Windows 7 SP1,Windows 8.1,Windows RT 8.1,Windows Server 2008
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Microsoft | Windows | 10 for 32-bit Systems |
affected |
10 for x64-based Systems |
affected | ||
10 Version 1607 for 32-bit Systems |
affected | ||
10 Version 1607 for x64-based Systems |
affected | ||
7 for 32-bit Systems Service Pack 1 |
affected | ||
7 for x64-based Systems Service Pack 1 |
affected | ||
8.1 for 32-bit systems |
affected | ||
8.1 for x64-based systems |
affected | ||
| … +1 more rows | |||
| Microsoft | Windows Server | 2016 |
affected |
2016 (Core installation) |
affected | ||
2008 for 32-bit Systems Service Pack 2 |
affected | ||
2008 for 32-bit Systems Service Pack 2 (Core installation) |
affected | ||
2008 for Itanium-Based Systems Service Pack 2 |
affected | ||
2008 for x64-based Systems Service Pack 2 |
affected | ||
2008 for x64-based Systems Service Pack 2 (Core installation) |
affected | ||
2008 R2 for Itanium-Based Systems Service Pack 1 |
affected | ||
| … +6 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Microsoft | Windows | 10 for 32-bit Systems | - |
|
| Microsoft | Windows Server | 2016 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | POC for cve-2019-1458 | https://github.com/piotrflorczyk/cve-2019-1458_POC | POC Details |
| 2 | CVE-2019-1458 Windows LPE Exploit | https://github.com/rip1s/CVE-2019-1458 | POC Details |
| 3 | None | https://github.com/Eternit7/CVE-2019-1458 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2019-1472 | Microsoft Windows Kernel 信息泄露漏洞 | |
| CVE-2019-1453 | Microsoft Remote Desktop Protocol 输入验证错误漏洞 | |
| CVE-2019-1400 | Microsoft Access 信息泄露漏洞 | |
| CVE-2019-1332 | Microsoft SQL Server Reporting Services 跨站脚本漏洞 | |
| CVE-2019-1461 | Microsoft Word 输入验证错误漏洞 | |
| CVE-2019-1463 | Microsoft Access 信息泄露漏洞 | |
| CVE-2019-1462 | Microsoft PowerPoint 输入验证错误漏洞 | |
| CVE-2019-1466 | Microsoft Windows Graphics Device Interface 信息泄露漏洞 | |
| CVE-2019-1465 | Microsoft Windows GDI 信息泄露漏洞 | |
| CVE-2019-1464 | Microsoft Excel 信息泄露漏洞 | |
| CVE-2019-1468 | Microsoft Windows和Microsoft Windows Server 输入验证错误漏洞 | |
| CVE-2019-1467 | Microsoft Windows GDI 信息泄露漏洞 | |
| CVE-2019-1470 | Microsoft Windows Hyper-V 信息泄露漏洞 | |
| CVE-2019-1469 | Microsoft Windows win32k组件信息泄露漏洞 | |
| CVE-2019-1474 | Microsoft Windows Kernel 信息泄露漏洞 | |
| CVE-2019-1490 | Microsoft Skype for Business Server 输入验证错误漏洞 | |
| CVE-2019-1471 | Micrsoft Windows Hyper-V 输入验证错误漏洞 | |
| CVE-2019-1477 | Microsoft Windows Windows Printer Service 安全漏洞 | |
| CVE-2019-1476 | Microsoft Windows和Microsoft Windows Server 安全漏洞 | |
| CVE-2019-1480 | Microsoft Windows Media Player 信息泄露漏洞 |
Showing top 20 of 30 CVEs. View all on vendor page → →
No comments yet