Back

HIGH

A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory

Published Apr 8, 2019

Description

A remote code execution vulnerability exists in the way that Windows Deployment Services TFTP Server handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with elevated permissions on a target system. To exploit the vulnerability, an attacker could create a specially crafted request, causing Windows to execute arbitrary code with elevated permissions. The security update addresses the vulnerability by correcting how Windows Deployment Services TFTP Server handles objects in memory, aka 'Windows Deployment Services TFTP Server Remote Code Execution Vulnerability'.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (0)

No CWE recorded.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner microsoft
Published Apr 8, 2019
Updated Aug 4, 2024
Reserved Nov 26, 2018

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner microsoft
Published Apr 8, 2019
Updated Aug 4, 2024

GitHub

No data