CVE-2019-0703
KEVmassWindows SMB Server Information Disclosure Vulnerability (CVE-2019-0703)
CISA: Microsoft Windows SMB Information Disclosure Vulnerability
CVE-2019-0703 is an information disclosure flaw in the way the Windows SMB Server handles certain requests, meaning the server can leak memory contents beyond what it should return in response to crafted SMB requests. Per its CVSS vector (AV:N/AC:L/PR:L), an attacker who can reach the SMB service and holds a low-privileged (valid) account can trigger the condition with no user interaction and no integrity or availability impact, but with high confidentiality impact. Affected systems are unpatched Windows 7, 8.1, RT 8.1, Windows 10 builds 1507 through 1809, Windows Server 2008, and Windows Server versions 1709 and 1803, on which the SMB Server is commonly enabled by default. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2022-05-23, confirming exploitation in the wild, although no public proof-of-concept is known and any ransomware association is unknown. The required action per CISA is to apply the vendor's updates.
What to do: Apply Microsoft's security updates for all affected Windows client and server versions, per the CISA KEV required action; for aged installs such as Windows 7 and Server 2008, confirm the patch is present or that extended-security-update coverage applies. Until patched, restrict SMB (TCP/445) exposure to trusted networks only and limit the availability of valid low-privileged credentials, since exploitation per the CVSS vector requires authentication. Prioritize systems that expose SMB externally and maintain an inventory of remaining unpatched hosts.
| Microsoft Windows 10 | 1507, 1607, 1703, 1709, 1803, 1809 |
| Microsoft Windows 7 | as listed in CPE data (all supported editions at time of disclosure) |
| Microsoft Windows 8.1 | as listed in CPE data (all supported editions at time of disclosure) |
| Microsoft Windows RT 8.1 | as listed in CPE data |
| Microsoft Windows Server 2008 | as listed in CPE data |
| Microsoft Windows Server (Semi-Annual Channel) | 1709, 1803 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0704, CVE-2019-0821.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows 7, windows 8.1, windows rt 8.1, windows server 1709, windows server 1803, windows server 2008
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N