CVE-2019-0865: Microsoft Windows 10

High severity, CVSS 7.5. EPSS: 4.5% chance of exploitation in the next 30 days.

A denial of service vulnerability exists when SymCrypt improperly handles a specially crafted digital signature.An attacker could exploit the vulnerability by creating a specially crafted connection or message.The security update addresses the vulnerability by correcting the way SymCrypt handles digital signatures., aka 'SymCrypt Denial of Service Vulnerability'.

Affected products

  • Microsoft Windows 10: version 1703 only; version 1709 only; version 1803 only; version 1809 only; version 1903 only
  • Microsoft Windows Server 2016: version 1803 only; version 1903 only
  • Microsoft Windows Server 2019: affected versions not specified

Published 2019-07-15. Last modified 2026-06-17.