CVE-2019-1040

MEDIUM EXPLOITED IN THE WILD

Microsoft Windows - Privilege Escalation

Title source: llm

Description

A tampering vulnerability exists in Microsoft Windows when a man-in-the-middle attacker is able to successfully bypass the NTLM MIC (Message Integrity Check) protection. An attacker who successfully exploited this vulnerability could gain the ability to downgrade NTLM security features. To exploit this vulnerability, the attacker would need to tamper with the NTLM exchange. The attacker could then modify flags of the NTLM packet without invalidating the signature. The update addresses the vulnerability by hardening NTLM MIC protection on the server-side.

Exploits (7)

nomisec SCANNER 301 stars
by fox-it · infoleak
https://github.com/fox-it/cve-2019-1040-scanner
nomisec WORKING POC 253 stars
by Ridter · remote-auth
https://github.com/Ridter/CVE-2019-1040
nomisec WORKING POC 72 stars
by QAX-A-Team · remote
https://github.com/QAX-A-Team/dcpwn
nomisec WORKING POC 33 stars
by Ridter · client-side
https://github.com/Ridter/CVE-2019-1040-dcpwn
nomisec WORKING POC 20 stars
by lazaars · client-side
https://github.com/lazaars/UltraRealy_with_CVE-2019-1040
nomisec WORKING POC
by JonyFilc · poc
https://github.com/JonyFilc/PrintSpoofer-ReflectiveDLL
patchapalooza WORKING POC
by godzeo · poc
https://gitee.com/godzeo/CVE-2019-1040

Scores

CVSS v3 5.3
EPSS 0.8968
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N

Details

VulnCheck KEV 2020-10-20
InTheWild.io 2020-12-23
Status published
Products (18)
microsoft/windows_10
microsoft/windows_10 1607
microsoft/windows_10 1703
microsoft/windows_10 1709
microsoft/windows_10 1803
microsoft/windows_10 1809
microsoft/windows_10 1903
microsoft/windows_7
microsoft/windows_8.1
microsoft/windows_rt_8.1
... and 8 more
Published Jun 12, 2019
Tracked Since Feb 18, 2026