HTTP: Microsoft Windows Driver CVE-2019-0628 Information Disclosure

This signature detects attempts to exploit a known vulnerability against Windows Kernal driver. Successful exploitation could result in Information Disclosure.

Extended Description

An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.

Affected Products

Microsoft windows_server_2016

References

CVE: CVE-2019-0628

Short Name
HTTP:STC:CVE-2019-0628-IN-DIS
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2019-0628 Disclosure Driver Information Microsoft Windows
Release Date
02/12/2019
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3590
False Positive
Unknown
Vendors

Microsoft

CVSS Score

2.1

Found a potential security threat?