CVE-2019-1343
MEDIUMWindows 10, 8.1, RT 8.1, Server 2012, 2016, 2019 - Denial of Service via Memory Object Handling
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-1343. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit demonstrates a Windows kernel crash (DoS) in nt!MiOffsetToProtos when loading a malformed PE image via LoadLibraryEx with specific flags. The issue is triggered by a corrupted .NET executable with modified SizeOfImage and CLR Runtime Header fields, causing a SYSTEM_SERVICE_EXCEPTION (0x3B) bugcheck.
Description
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-1346, CVE-2019-1347.
Exploits (1)
This exploit demonstrates a Windows kernel crash (DoS) in nt!MiOffsetToProtos when loading a malformed PE image via LoadLibraryEx with specific flags. The issue is triggered by a corrupted .NET executable with modified SizeOfImage and CLR Runtime Header fields, causing a SYSTEM_SERVICE_EXCEPTION (0x3B) bugcheck.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H