packetstormsecurity.com
http://packetstormsecurity.com/files/154084/Microsoft-Font-Subsetting-DLL-GetGlyphId-Out-Of-Bounds-Read.html CVE-2019-1148
MEDIUM
Microsoft Graphics Component Information Disclosure Vulnerability
Record summary
CVE-2019-1148 has a selected CVSS score of 5.5 (medium); EIP currently links 1 catalogued exploit.
Description
An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1078, CVE-2019-1153.
Description source: GitHub Advisory
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 16, 2024 · Source: CVE List
Affected products and versions
Showing 12 of 29| Product | Source | Version range | Status |
|---|---|---|---|
Microsoft Office 2019 for MacBrowse Microsoft / Microsoft Office 2019 for Mac | CVE List | 16.0.0 to < publication | affected |
Windows 10 Version 1507Browse Microsoft / Windows 10 Version 1507 | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 1607Browse Microsoft / Windows 10 Version 1607 | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 1703Browse Microsoft / Windows 10 Version 1703 | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 1709Browse Microsoft / Windows 10 Version 1709 | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 1709 for 32-bit SystemsBrowse Microsoft / Windows 10 Version 1709 for 32-bit Systems | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 1803Browse Microsoft / Windows 10 Version 1803 | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 1809Browse Microsoft / Windows 10 Version 1809 | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 1903 for 32-bit SystemsBrowse Microsoft / Windows 10 Version 1903 for 32-bit Systems | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 1903 for ARM64-based SystemsBrowse Microsoft / Windows 10 Version 1903 for ARM64-based Systems | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 1903 for x64-based SystemsBrowse Microsoft / Windows 10 Version 1903 for x64-based Systems | CVE List | 10.0.0 to < publication | affected |
Windows 7Browse Microsoft / Windows 7 | CVE List | 6.1.0 to < publication | affected |
Proofs of concept
1Catalogued exploits
ExploitDBMicrosoft Font Subsetting - DLL Heap-Based Out-of-Bounds read in GetGlyphIdxExploitDB exploitby Google Security ResearchNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-1148 portal.msrc.microsoft.com
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1148