Apr 2019:
CVE-2019-0703 Published on April 9, 2019
An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0704, CVE-2019-0821.
Known Exploited Vulnerability
This Microsoft Windows SMB Information Disclosure Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, which could lead to information disclosure from the server.
The following remediation steps are recommended / required by June 13, 2022: Apply updates per vendor instructions.
Vulnerability Analysis
CVE-2019-0703 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. This vulnerability is known to be actively exploited by threat actors. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Products Associated with CVE-2019-0703
Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.
Affected Versions
Microsoft Windows:- Version 7 for 32-bit Systems Service Pack 1 is affected.
- Version 7 for x64-based Systems Service Pack 1 is affected.
- Version 8.1 for 32-bit systems is affected.
- Version 8.1 for x64-based systems is affected.
- Version RT 8.1 is affected.
- Version 10 for 32-bit Systems is affected.
- Version 10 for x64-based Systems is affected.
- Version 10 Version 1607 for 32-bit Systems is affected.
- Version 10 Version 1607 for x64-based Systems is affected.
- Version 10 Version 1703 for 32-bit Systems is affected.
- Version 10 Version 1703 for x64-based Systems is affected.
- Version 10 Version 1709 for 32-bit Systems is affected.
- Version 10 Version 1709 for x64-based Systems is affected.
- Version 10 Version 1803 for 32-bit Systems is affected.
- Version 10 Version 1803 for x64-based Systems is affected.
- Version 10 Version 1803 for ARM64-based Systems is affected.
- Version 10 Version 1809 for 32-bit Systems is affected.
- Version 10 Version 1709 for ARM64-based Systems is affected.
- Version 2008 R2 for x64-based Systems Service Pack 1 (Core installation) is affected.
- Version n/a is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.