Vulnerability record · CVE-2019-0703 · published 9 April 2019
CVE-2019-0703: Windows SMB Server information disclosure flaw
Microsoft · Windows 10 1507
CVE-2019-0703 is an information disclosure vulnerability in the way the Windows SMB Server handles certain requests. A network attacker with low privileges can cause the server to leak information; the record does not specify what data is exposed or the exact request handling defect.
Description
An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0704, CVE-2019-0821.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityThe flaw is confirmed exploited in the wild per CISA KEV and affects a broad set of Windows and Windows Server versions, though it is limited to information disclosure with low privileges required.
What it is
CVE-2019-0703 is an information disclosure vulnerability in the way the Windows SMB Server handles certain requests. A network attacker with low privileges can cause the server to leak information; the record does not specify what data is exposed or the exact request handling defect.
Impact
An attacker gains unauthorized read access to information held or processed by the SMB server, with high confidentiality impact but no integrity or availability effect. The specific leaked data is not described in the record.
Attack surface
Reached over the network via SMB (CVSS vector AV:N) with low privileges required (PR:L) and no user interaction (UI:N). No authentication-free path is indicated; the attacker needs at least a low-privileged account or session.
Exploitation
CVE-2019-0703 is listed in CISA KEV (added 2022-05-23), indicating known exploitation in the wild, and EPSS gives a 30-day probability of about 9.6 percent (95th percentile). No ransomware campaign use is recorded.
What to do
- Apply the Microsoft security update referenced in the vendor advisory for all affected Windows and Windows Server versions.
- Restrict SMB exposure: block TCP 445 and 139 at network boundaries and segment SMB traffic to trusted hosts only.
- Enforce least privilege so low-privileged accounts cannot reach SMB services unnecessarily.
- Monitor vendor advisories for superseding updates and verify patch status across the listed Windows 7, 8.1, 10 and Server builds.
Detection
- Review SMB server logs and network flow data for anomalous or malformed request patterns against hosts running unpatched Windows versions.
- Alert on SMB connections from low-privileged or unusual accounts to servers that should not receive them.
- Correlate host patch inventory against the affected Windows and Windows Server builds to find unpatched SMB servers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-0703 to the Known Exploited Vulnerabilities catalog on 23 May 2022 as "Microsoft Windows SMB Information Disclosure Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 13 June 2022.
Affected products
15 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0703 | PatchVendor Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0703 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0703 | US Government Resource |
Track CVE-2019-0703 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-0703), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.