ZeroHour

CVE-2019-0703

KEVmass

Windows SMB Server Information Disclosure Vulnerability (CVE-2019-0703)

CISA: Microsoft Windows SMB Information Disclosure Vulnerability

CVSS 3.1
6.5 medium
EPSS
10%p95
Published
()
KEV added
AI analysis

CVE-2019-0703 is an information disclosure flaw in the way the Windows SMB Server handles certain requests, meaning the server can leak memory contents beyond what it should return in response to crafted SMB requests. Per its CVSS vector (AV:N/AC:L/PR:L), an attacker who can reach the SMB service and holds a low-privileged (valid) account can trigger the condition with no user interaction and no integrity or availability impact, but with high confidentiality impact. Affected systems are unpatched Windows 7, 8.1, RT 8.1, Windows 10 builds 1507 through 1809, Windows Server 2008, and Windows Server versions 1709 and 1803, on which the SMB Server is commonly enabled by default. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2022-05-23, confirming exploitation in the wild, although no public proof-of-concept is known and any ransomware association is unknown. The required action per CISA is to apply the vendor's updates.

What to do: Apply Microsoft's security updates for all affected Windows client and server versions, per the CISA KEV required action; for aged installs such as Windows 7 and Server 2008, confirm the patch is present or that extended-security-update coverage applies. Until patched, restrict SMB (TCP/445) exposure to trusted networks only and limit the availability of valid low-privileged credentials, since exploitation per the CVSS vector requires authentication. Prioritize systems that expose SMB externally and maintain an inventory of remaining unpatched hosts.

Affected
Microsoft Windows 101507, 1607, 1703, 1709, 1803, 1809
Microsoft Windows 7as listed in CPE data (all supported editions at time of disclosure)
Microsoft Windows 8.1as listed in CPE data (all supported editions at time of disclosure)
Microsoft Windows RT 8.1as listed in CPE data
Microsoft Windows Server 2008as listed in CPE data
Microsoft Windows Server (Semi-Annual Channel)1709, 1803
Estimated exposure
masshundreds of millions of Windows client and server installations (SMB Server is enabled by default on essentially all Windows systems) — SMB is a default-enabled service on effectively every Windows 7/8.1/10 and Windows Server system in the affected version list, product families that collectively ran on hundreds of millions of devices when the flaw was disclosed.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0704, CVE-2019-0821.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows 7, windows 8.1, windows rt 8.1, windows server 1709, windows server 1803, windows server 2008
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news