CVE-2019-1314 is a security feature bypass vulnerability affecting Windows 10 Mobile, where the Cortana voice assistant could be leveraged to access files and folders from a locked device. This vulnerability carries a CVSS score of 6.8 (Medium), indicating a physical attack vector with low complexity, allowing for high impact on confidentiality, integrity, and availability. While the EPSS and FAUCET scores suggest a relatively low overall risk, the potential for complete compromise of the device is significant. There is no known public exploit code (Metasploit, Nuclei, ExploitDB) and it is not listed in the KEV catalog, suggesting it is not actively exploited in the wild. Community discussion and media coverage are minimal, with only one article mentioning its fix in a broader Patch Tuesday update.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_mobile:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.