CVE Published: 16/05/2019 |
CVE Updated: 04/08/2024 |
CVE Year: 2019 Source: microsoft |
Vendor: Microsoft |
Product: Windows Server Status : PUBLISHED
CVE-2019-0707 Description
An elevation of privilege vulnerability exists in the Network Driver Interface Specification (NDIS) when ndis.sys fails to check the length of a buffer prior to copying memory to it.To exploit the vulnerability, in a local attack scenario, an attacker could run a specially crafted application to elevate the attacker\'s privilege level, aka \'Windows NDIS Elevation of Privilege Vulnerability\'.