V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2019-0948
MSR
MediumConfirmedExploit available

An information disclosure vulnerability exists in the Windows Event Viewer (eventvwr.msc) when it improperly parses XML input containing a …

CVSS
4.7
Medium
EPSS
0.41
p97
Published
2019-01-01
Updated
2019-01-01
Description

An information disclosure vulnerability exists in the Windows Event Viewer (eventvwr.msc) when it improperly parses XML input containing a reference to an external entity. An attacker who successfully exploited this vulnerability could read arbitrary files via an XML external entity (XXE) declaration. To exploit the vulnerability, an attacker could create a file containing specially crafted XML content and convince an authenticated user to import the file. The update addresses the vulnerability by modifying the way that the Event Viewer parses XML input.

Tags · CWE
CWE-611
CAPEC-221
Affected products
Windows_10Windows_7Windows_8.1Windows_rt_8.1Windows_server_2008Windows_server_2012Windows_server_2016Windows_server_2019
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Timeline
2019-01-01
Published
2019-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: H
High (H)
Privileges Required
PR: N
None (N)
User Interaction
UI: R
Required (R)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.414 · p97
Known exploited (KEV)
No
Known exploits — Сканер-ВС
40863
exploitdb · https://www.exploit-db.com/exploits/40863
Enterprise
Affected software
ProductVendorStatus
windows_10*Tracked
windows_7*Tracked
windows_8.1*Tracked
windows_rt_8.1*Tracked
windows_server_2008*Tracked
windows_server_2012*Tracked
windows_server_2016*Tracked
windows_server_2019*Tracked
WindowsMicrosoftTracked
WindowsMicrosoftTracked
WindowsMicrosoftTracked
WindowsMicrosoftTracked
WindowsMicrosoftTracked
WindowsMicrosoftTracked
WindowsMicrosoftTracked
WindowsMicrosoftTracked
WindowsMicrosoftTracked
WindowsMicrosoftTracked
WindowsMicrosoftTracked
WindowsMicrosoftTracked