Record summary

CVE-2019-1153 has a selected CVSS score of 5.5 (medium); EIP currently links 1 catalogued exploit.

Description

An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1078, CVE-2019-1148.

Description source: GitHub Advisory

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 1, 2024 · Source: CVE List

Affected products and versions

Showing 12 of 29
ProductSourceVersion rangeStatus
CVE List16.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected

Windows 10 Version 1709 for 32-bit Systems

Browse Microsoft / Windows 10 Version 1709 for 32-bit Systems
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected

Windows 10 Version 1903 for 32-bit Systems

Browse Microsoft / Windows 10 Version 1903 for 32-bit Systems
CVE List10.0.0 to < publicationaffected

Windows 10 Version 1903 for ARM64-based Systems

Browse Microsoft / Windows 10 Version 1903 for ARM64-based Systems
CVE List10.0.0 to < publicationaffected

Windows 10 Version 1903 for x64-based Systems

Browse Microsoft / Windows 10 Version 1903 for x64-based Systems
CVE List10.0.0 to < publicationaffected
CVE List6.1.0 to < publicationaffected

Proofs of concept

1

Catalogued exploits

ExploitDBMicrosoft Font Subsetting - DLL Heap-Based Out-of-Bounds read in FixSbitSubTableFormat1ExploitDB exploitby Google Security ResearchNot analyzed1 file
ExploitDB

PoC details

References

3