Windows Kernel Information Disclosure Vulnerability
Published Sep 3, 2019
5.6
MEDIUMCVSS 3.1
EPSS 4.52%
Description
An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would not allow an attacker to elevate user rights directly, but it could be used to obtain information that could be used to try to compromise the affected system further. On January 3, 2018, Microsoft released an advisory and security updates related to a newly-discovered class of hardware vulnerabilities (known as Spectre) involving speculative execution side channels that affect AMD, ARM, and Intel CPUs to varying degrees. This vulnerability, released on August 6, 2019, is a variant of the Spectre Variant 1 speculative execution side channel vulnerability and has been assigned CVE-2019-1125. Microsoft released a security update on July 9, 2019 that addresses the vulnerability through a software change that mitigates how the CPU speculatively accesses memory. Note that this vulnerability does not require a microcode update from your device OEM.
Affected products
-
- Version 10.0.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.0StatusaffectedConstraints<publication
- Version
-
- Version 6.1.0StatusaffectedConstraints<publication
- Version
-
- Version 6.1.0StatusaffectedConstraints<publication
- Version
-
- Version 6.3.0StatusaffectedConstraints<publication
- Version
-
- Version 6.0.0StatusaffectedConstraints<publication
- Version
-
- Version 6.1.0StatusaffectedConstraints<publication
- Version
- Vendor Microsoft Product Windows Server 2008 R2 Service Pack 1 (Server Core installation) Defaultn/a
- Version 6.0.0StatusaffectedConstraints<publication
- Version
-
- Version 6.1.0StatusaffectedConstraints<publication
- Version
-
- Version 6.0.0StatusaffectedConstraints<publication
- Version
-
- Version 6.0.0StatusaffectedConstraints<publication
- Version
-
- Version 6.2.0StatusaffectedConstraints<publication
- Version
-
- Version 6.2.0StatusaffectedConstraints<publication
- Version
-
- Version 6.3.0StatusaffectedConstraints<publication
- Version
-
- Version 6.3.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.0StatusaffectedConstraints<publication
- Version
-
- Version 10.0.0StatusaffectedConstraints<publication
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Microsoft | Windows 10 Version 1507 | n/a |
| ||||||
| Microsoft | Windows 10 Version 1607 | n/a |
| ||||||
| Microsoft | Windows 10 Version 1703 | n/a |
| ||||||
| Microsoft | Windows 10 Version 1709 | n/a |
| ||||||
| Microsoft | Windows 10 Version 1709 for 32-bit Systems | n/a |
| ||||||
| Microsoft | Windows 10 Version 1803 | n/a |
| ||||||
| Microsoft | Windows 10 Version 1809 | n/a |
| ||||||
| Microsoft | Windows 10 Version 1903 for 32-bit Systems | n/a |
| ||||||
| Microsoft | Windows 10 Version 1903 for ARM64-based Systems | n/a |
| ||||||
| Microsoft | Windows 10 Version 1903 for x64-based Systems | n/a |
| ||||||
| Microsoft | Windows 7 | n/a |
| ||||||
| Microsoft | Windows 7 Service Pack 1 | n/a |
| ||||||
| Microsoft | Windows 8.1 | n/a |
| ||||||
| Microsoft | Windows Server 2008 Service Pack 2 | n/a |
| ||||||
| Microsoft | Windows Server 2008 R2 Service Pack 1 | n/a |
| ||||||
| Microsoft | Windows Server 2008 R2 Service Pack 1 (Server Core installation) | n/a |
| ||||||
| Microsoft | Windows Server 2008 R2 Systems Service Pack 1 | n/a |
| ||||||
| Microsoft | Windows Server 2008 Service Pack 2 | n/a |
| ||||||
| Microsoft | Windows Server 2008 Service Pack 2 (Server Core installation) | n/a |
| ||||||
| Microsoft | Windows Server 2012 | n/a |
| ||||||
| Microsoft | Windows Server 2012 (Server Core installation) | n/a |
| ||||||
| Microsoft | Windows Server 2012 R2 | n/a |
| ||||||
| Microsoft | Windows Server 2012 R2 (Server Core installation) | n/a |
| ||||||
| Microsoft | Windows Server 2016 | n/a |
| ||||||
| Microsoft | Windows Server 2016 (Server Core installation) | n/a |
| ||||||
| Microsoft | Windows Server 2019 | n/a |
| ||||||
| Microsoft | Windows Server 2019 (Server Core installation) | n/a |
| ||||||
| Microsoft | Windows Server, version 1803 (Server Core Installation) | n/a |
| ||||||
| Microsoft | Windows Server, version 1903 (Server Core installation) | n/a |
|
Configuration 1
- n/a
- 1607
- 1703
- 1709
- 1803
- 1809
- 1903
- n/a
- n/a
- n/a
- n/a
- r2
- r2
- n/a
- r2
- n/a
- 1803
- 1903
- n/a
Configuration 2
- 4.0
- 7.0
- 7.0
- 7.7
- 7.7
- 7.7
- 7.0
No data.
Red Hat Enterprise Linux 6
kernel-0:2.6.32-754.18.2.el6
Fixed · RHSA-2019:2473
Red Hat Enterprise Linux 6.5 Advanced Update Support
kernel-0:2.6.32-431.96.1.el6
Fixed · RHSA-2019:2695
Red Hat Enterprise Linux 6.6 Advanced Update Support
kernel-0:2.6.32-504.80.2.el6
Fixed · RHSA-2019:2476
Red Hat Enterprise Linux 7
kernel-0:3.10.0-1062.1.1.el7
Fixed · RHSA-2019:2600
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-1062.1.1.rt56.1024.el7
Fixed · RHSA-2019:2609
Red Hat Enterprise Linux 7.2 Advanced Update Support
kernel-0:3.10.0-327.82.1.el7
Fixed · RHSA-2019:2899
Red Hat Enterprise Linux 7.2 Telco Extended Update Support
kernel-0:3.10.0-327.82.1.el7
Fixed · RHSA-2019:2899
Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions
kernel-0:3.10.0-327.82.1.el7
Fixed · RHSA-2019:2899
Red Hat Enterprise Linux 7.3 Advanced Update Support
kernel-0:3.10.0-514.69.1.el7
Fixed · RHSA-2019:2900
Red Hat Enterprise Linux 7.3 Telco Extended Update Support
kernel-0:3.10.0-514.69.1.el7
Fixed · RHSA-2019:2900
Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions
kernel-0:3.10.0-514.69.1.el7
Fixed · RHSA-2019:2900
Red Hat Enterprise Linux 7.4 Extended Update Support
kernel-0:3.10.0-693.58.1.el7
Fixed · RHSA-2019:2696
Red Hat Enterprise Linux 7.5 Extended Update Support
kernel-0:3.10.0-862.43.1.el7
Fixed · RHSA-2019:2975
Red Hat Enterprise Linux 7.6 Extended Update Support
kernel-0:3.10.0-957.38.1.el7
Fixed · RHSA-2019:3220
Red Hat Enterprise Linux 8
kernel-0:4.18.0-80.7.2.el8_0
Fixed · RHSA-2019:2411
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-80.7.2.rt9.154.el8_0
Fixed · RHSA-2019:2405
Red Hat Enterprise MRG 2
kernel-rt-1:3.10.0-693.58.1.rt56.652.el6rt
Fixed · RHSA-2019:2730
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
imgbased-0:1.1.10-0.1.el7ev
Fixed · RHSA-2019:3011
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
ovirt-node-ng-0:4.3.6-0.20190820.0.el7ev
Fixed · RHSA-2019:3011
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
redhat-release-virtualization-host-0:4.3.6-2.el7ev
Fixed · RHSA-2019:3011
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
redhat-virtualization-host-0:4.3.6-20190924.0.el7_7
Fixed · RHSA-2019:3011
Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS
kernel-0:3.10.0-957.38.1.el7
Fixed · RHSA-2019:3220
Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS
redhat-release-virtualization-host-0:4.2-15.1.el7
Fixed · RHBA-2019:3248
Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS
redhat-virtualization-host-0:4.2-20191022.0.el7_6
Fixed · RHBA-2019:3248
Red Hat Enterprise Linux 5
kernel
Affected
Red Hat Enterprise Linux 7
kernel-alt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-754.18.2.el6 | Fixed | RHSA-2019:2473 |
| Red Hat Enterprise Linux 6.5 Advanced Update Support | kernel-0:2.6.32-431.96.1.el6 | Fixed | RHSA-2019:2695 |
| Red Hat Enterprise Linux 6.6 Advanced Update Support | kernel-0:2.6.32-504.80.2.el6 | Fixed | RHSA-2019:2476 |
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-1062.1.1.el7 | Fixed | RHSA-2019:2600 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-1062.1.1.rt56.1024.el7 | Fixed | RHSA-2019:2609 |
| Red Hat Enterprise Linux 7.2 Advanced Update Support | kernel-0:3.10.0-327.82.1.el7 | Fixed | RHSA-2019:2899 |
| Red Hat Enterprise Linux 7.2 Telco Extended Update Support | kernel-0:3.10.0-327.82.1.el7 | Fixed | RHSA-2019:2899 |
| Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions | kernel-0:3.10.0-327.82.1.el7 | Fixed | RHSA-2019:2899 |
| Red Hat Enterprise Linux 7.3 Advanced Update Support | kernel-0:3.10.0-514.69.1.el7 | Fixed | RHSA-2019:2900 |
| Red Hat Enterprise Linux 7.3 Telco Extended Update Support | kernel-0:3.10.0-514.69.1.el7 | Fixed | RHSA-2019:2900 |
| Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions | kernel-0:3.10.0-514.69.1.el7 | Fixed | RHSA-2019:2900 |
| Red Hat Enterprise Linux 7.4 Extended Update Support | kernel-0:3.10.0-693.58.1.el7 | Fixed | RHSA-2019:2696 |
| Red Hat Enterprise Linux 7.5 Extended Update Support | kernel-0:3.10.0-862.43.1.el7 | Fixed | RHSA-2019:2975 |
| Red Hat Enterprise Linux 7.6 Extended Update Support | kernel-0:3.10.0-957.38.1.el7 | Fixed | RHSA-2019:3220 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-80.7.2.el8_0 | Fixed | RHSA-2019:2411 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-80.7.2.rt9.154.el8_0 | Fixed | RHSA-2019:2405 |
| Red Hat Enterprise MRG 2 | kernel-rt-1:3.10.0-693.58.1.rt56.652.el6rt | Fixed | RHSA-2019:2730 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | imgbased-0:1.1.10-0.1.el7ev | Fixed | RHSA-2019:3011 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | ovirt-node-ng-0:4.3.6-0.20190820.0.el7ev | Fixed | RHSA-2019:3011 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-release-virtualization-host-0:4.3.6-2.el7ev | Fixed | RHSA-2019:3011 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | redhat-virtualization-host-0:4.3.6-20190924.0.el7_7 | Fixed | RHSA-2019:3011 |
| Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS | kernel-0:3.10.0-957.38.1.el7 | Fixed | RHSA-2019:3220 |
| Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS | redhat-release-virtualization-host-0:4.2-15.1.el7 | Fixed | RHBA-2019:3248 |
| Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS | redhat-virtualization-host-0:4.2-20191022.0.el7_6 | Fixed | RHBA-2019:3248 |
| Red Hat Enterprise Linux 5 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security is aware of this issue. Updates will be released as they become available. For additional information, please refer to the Red Hat Knowledgebase article: https://access.redhat.com/articles/4329821
Red Hat mitigation
For mitigation related information, please refer to the Red Hat Knowledgebase article: https://access.redhat.com/articles/4329821
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N/E:P/RL:O/RC:C
1 other source (NVD) ▾
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
AV:L/AC:L/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (26 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.52% (0.04521) | 91.23th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.52% (0.04521) | 90.28th | v5 (v2026.06.15) |
| May 3, 2026 | 19.22% (0.19224) | 95.39th | v4 (v2025.03.14) |
| Nov 16, 2025 | 17.04% (0.17044) | 94.71th | v4 (v2025.03.14) |
| Aug 30, 2025 | 13.43% (0.13431) | 93.94th | v4 (v2025.03.14) |
| Mar 30, 2025 | 15.10% (0.15102) | 94.01th | v4 (v2025.03.14) |
| Mar 29, 2025 | 26.94% (0.26940) | 94.18th | v4 (v2025.03.14) |
| Mar 28, 2025 | 15.10% (0.15102) | 94.02th | v4 (v2025.03.14) |
| Mar 27, 2025 | 26.94% (0.26940) | 95.65th | v4 (v2025.03.14) |
| Mar 20, 2025 | 15.10% (0.15102) | 94.08th | v4 (v2025.03.14) |
| Mar 19, 2025 | 26.94% (0.26940) | 95.74th | v4 (v2025.03.14) |
| Mar 17, 2025 | 15.10% (0.15102) | 94.07th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.12% (0.00118) | 47.34th | v3 (v2023.03.01) |
| May 30, 2024 | 0.08% (0.00082) | 34.89th | v3 (v2023.03.01) |
| Mar 16, 2024 | 0.17% (0.00165) | 52.12th | v3 (v2023.03.01) |
| Aug 27, 2023 | 0.12% (0.00120) | 45.39th | v3 (v2023.03.01) |
| Aug 10, 2023 | 0.15% (0.00155) | 51.08th | v3 (v2023.03.01) |
| Jun 5, 2023 | 0.12% (0.00119) | 44.73th | v3 (v2023.03.01) |
| May 3, 2023 | 0.08% (0.00080) | 32.74th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.07% (0.00066) | 27.21th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.64% (0.02641) | 82.21th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.64% (0.02641) | 80.45th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.64% (0.02641) | 61.81th | v2 (v2022.01.01) |
| Feb 3, 2022 | 66.20% (0.66201) | 99.36th | v1 |
| Sep 1, 2021 | 66.20% (0.66201) | 99.82th | v1 |
| Apr 14, 2021 | 66.20% (0.66201) | 0.00th | v1 |
References (21)
- http://packetstormsecurity.com/files/156337/SWAPGS-Attack-Proof-Of-Concept.html x_refsource_MISC
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200408-01-swapgs-en x_refsource_CONFIRM
- https://access.redhat.com/errata/RHBA-2019:2824 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHBA-2019:3248 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:2600 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2609 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:2695 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:2696 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:2730 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:2899 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:2900 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:2975 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:3011 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:3220 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2019-1125 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1724389 Issue Tracking
- https://kc.mcafee.com/corporate/index?page=content&id=SB10297 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2019-1125
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1125 x_refsource_MISCPatchVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-1125
- https://www.synology.com/security/advisory/Synology_SA_19_32 x_refsource_CONFIRM
Change history (0)
No recorded changes yet.