Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2019-1314

Опубликовано: 08 окт. 2019
Источник: msrc
EPSS Низкий

Описание

Windows 10 Mobile Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists in Windows 10 Mobile when Cortana allows a user to access files and folders through the locked screen. An attacker who successfully exploited this vulnerability could access the photo library of an affected phone and modify or delete photos without authenticating to the system.

To exploit the vulnerability, an attacker would require physical access and the phone would need to have Cortana assistance allowed from the lock screen.

Обходное решение

The following workaround can protect users from this vulnerability by disabling access to Cortana on the phone lock screen. This can be accomplished by following these steps:

  1. Open the Cortana app from the applications screen.
  2. Tap on the Menu button (3 horizontal bars) in the top left of the Cortana app.
  3. Tap on Settings option.
  4. Set the slider for the Lock Screen option to Off to prevent access to Cortana when the device is locked.

FAQ

Where do I find the update for Windows 10 Mobile?

Microsoft is not planning on fixing this vulnerability in Windows 10 Mobile. Microsoft recommends implementing the workaround to restrict access to Cortana.

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 45%
0.00221
Низкий

Связанные уязвимости

CVSS3: 6.8
nvd
почти 6 лет назад

A security feature bypass vulnerability exists in Windows 10 Mobile when Cortana allows a user to access files and folders through the locked screen, aka 'Windows 10 Mobile Security Feature Bypass Vulnerability'.

github
больше 3 лет назад

A security feature bypass vulnerability exists in Windows 10 Mobile when Cortana allows a user to access files and folders through the locked screen, aka 'Windows 10 Mobile Security Feature Bypass Vulnerability'.

CVSS3: 6.8
fstec
почти 6 лет назад

Уязвимость голосового помощника Cortana операционных систем Windows 10 Mobile, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 45%
0.00221
Низкий