CVE-2019-1148
high-risk
Published 2019-08-14
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The update addresses the vulnerability by correcting the way in which the Windows Graphics Component handles objects in memory.
Do I need to act?
~
4.2% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
!
1 public exploit available
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
5
CVSS 5.5/10
Medium
LOCAL
/ LOW complexity
Affected Products (20)
Affected Vendors
References (4)
Third Party Advisory
http://packetstormsecurity.com/files/154084/Microsoft-Font-Subsetting-DLL-GetGly...
Third Party Advisory
http://packetstormsecurity.com/files/154084/Microsoft-Font-Subsetting-DLL-GetGly...
52
/ 100
high-risk
Severity
18/34 · Moderate
Exploitability
14/34 · Moderate
Exposure
20/34 · Moderate