CVE-2019-1019
CVSS v3
8.5
HIGH
EPSS Score
15.1 %
exploit probability, as of 2026-10-05
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages. To exploit this vulnerability, an attacker could send a specially crafted authentication request. An attacker who successfully exploited this vulnerability could access another machine using the original user privileges. The issue has been addressed by changing how NTLM validates network authentication messages.
Technical details
- Published
- 2019-06-12
- Exploit-DB
- EDB-47115
Frequently asked questions
What is CVE-2019-1019?
A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages. To exploit this vulnerability, an attacker could send a specially crafted authentication request. An attacker who successfully exploited this vulnerability could access another machine using the original user privileges. The issue has been addressed by changing how NTLM validates network authentication messages.
Is CVE-2019-1019 actively exploited?
Active exploitation of CVE-2019-1019 has not been confirmed. Its EPSS score was 15.1% on 2026-10-05, the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2019-1019?
CVE-2019-1019 has a CVSS v3 base score of 8.5 (HIGH severity).
Is CVE-2019-1019 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 50 free checks/month · Free API key
Other 2019 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).