Cyber Resilience

CVE-2019-0703

Microsoft Windows 10 1809

CISA KEVActive ExploitationEUVD Exploited
Published
09 April 2019
Modified
29 October 2025
KEV Added
23 May 2022
Patch / advisory
CVSS Score v3.1 6.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.096 95th percentile
Risk Priority 76 floored blend · peak EPSS

Summary

CVE-2019-0703 is a medium-severity an unspecified weakness vulnerability in Microsoft Windows 10 1809. Its CVSS base score is 6.5 (Medium).

Operationally, ranked in the top 5% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests. This affects the Server Message Block component in Windows and is tracked separately from the related issues CVE-2019-0704 and CVE-2019-0821. The flaw carries a CVSS 3.1 score of 6.5 reflecting network attack vector, low complexity, and low privileges required.

An authenticated attacker with network access can send specially crafted requests to disclose sensitive information from the target system, with no user interaction needed and no impact on integrity or availability.

Microsoft has published security guidance and patches for the issue through its MSRC advisory portal. The vulnerability is also catalogued by CISA as one known to have been exploited in the wild.

EU & UK References

Vulnerability Data

An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0704, CVE-2019-0821.

CWE(s)
KEV Date Added
23 May 2022

Related Threats

CVEs Like This One

CVE-2019-0859Same product: Microsoft Windows 10 1507both on KEV
CVE-2019-0543Same product: Microsoft Windows 10 1507both on KEV
CVE-2018-8453Same product: Microsoft Windows 10 1507both on KEV
CVE-2019-0803Same product: Microsoft Windows 10 1507both on KEV
CVE-2018-8639Same product: Microsoft Windows 10 1507both on KEV
CVE-2019-0797Same product: Microsoft Windows 10 1507both on KEV
CVE-2018-0824Same product: Microsoft Windows 10 1507both on KEV
CVE-2019-0903Same product: Microsoft Windows 10 1507both on KEV
CVE-2019-0863Same product: Microsoft Windows 10 1507both on KEV
CVE-2019-1215Same product: Microsoft Windows 10 1507both on KEV

Affected Assets

microsoft
windows 10 1507
all versions
microsoft
windows 10 1607
all versions
microsoft
windows 10 1703
all versions
microsoft
windows 10 1709
all versions
microsoft
windows 10 1803
all versions
microsoft
windows 10 1809
all versions
microsoft
windows 7
all versions
microsoft
windows 8.1
all versions
microsoft
windows rt 8.1
all versions
microsoft
windows server 1709
all versions
+5 more product configuration(s) — see NVD for full list

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References