VYPR
Medium severity4.4NVD Advisory· Published Jun 12, 2019· Updated Jun 17, 2026

CVE-2019-0941

CVE-2019-0941

Description

A denial of service exists in Microsoft IIS Server when the optional request filtering feature improperly handles requests. An attacker who successfully exploited this vulnerability could perform a temporary denial of service against pages configured to use request filtering. To exploit this vulnerability, an attacker could send a specially crafted request to a page utilizing request filtering. The update addresses the vulnerability by changing the way certain requests are processed by the filter.

Affected products

48
  • cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*+ 7 more
    • cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_10:1903:*:*:*:*:*:*:*
    • (no CPE)range: 10.0.10240.0
  • cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*
    • (no CPE)range: 6.1.0
  • cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*
    • (no CPE)range: 6.3.0
  • cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*+ 4 more
    • cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*
    • (no CPE)range: 6.0.6003.0
    • (no CPE)range: 6.1.7601.0
    • (no CPE)range: 6.0.0
  • cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
    • (no CPE)range: 6.2.9200.0
    • (no CPE)range: 6.3.9600.0
  • cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_server_2016:1803:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_server_2016:1903:*:*:*:*:*:*:*
    • (no CPE)range: 10.0.14393.0
  • cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*
    • (no CPE)range: 10.0.17763.0
  • Range: 10.0.14393.0
  • Range: 10.0.0
  • Range: 10.0.0
  • Microsoft/Windows 10 Version 1709 for 32-bit Systemsv5
    Range: 10.0.0
  • Microsoft/Windows 10 Version 1803v5
    Range: 10.0.0
  • Range: 10.0.17763.0
  • Microsoft/Windows 10 Version 1903 for 32-bit Systemsv5
    Range: 10.0.0
  • Microsoft/Windows 10 Version 1903 for ARM64-based Systemsv5
    Range: 10.0.0
  • Microsoft/Windows 10 Version 1903 for x64-based Systemsv5
    Range: 10.0.0
  • Range: 6.1.0
  • Microsoft/Windows Server 2008 R2 Service Pack 1 (Server Core installation)v5
    Range: 6.1.7601.0
  • Microsoft/Windows Server 2008 R2 Systems Service Pack 1v5
    Range: 6.1.0
  • Microsoft/Windows Server 2008 Service Pack 2 (Server Core installation)v5
    Range: 6.0.6003.0
  • Microsoft/Windows Server 2012 (Server Core installation)v5
    Range: 6.2.9200.0
  • Microsoft/Windows Server 2012 R2 (Server Core installation)v5
    Range: 6.3.9600.0
  • Microsoft/Windows Server 2016 (Server Core installation)v5
    Range: 10.0.14393.0
  • Microsoft/Windows Server 2019 (Server Core installation)v5
    Range: 10.0.17763.0
  • Microsoft/Windows Server, version 1803 (Server Core Installation)v5
    Range: 10.0.0
  • Microsoft/Windows Server, version 1903 (Server Core installation)v5
    Range: 10.0.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.