CVE-2019-0543
KEV ransomware PoC massLocal Privilege Escalation (Improper Authentication) in Windows 7/8.1/10 and Server
CISA: Microsoft Windows Privilege Escalation Vulnerability
CVE-2019-0543 is an elevation-of-privilege flaw (CWE-287, improper authentication) that exists when Windows improperly handles authentication requests, affecting Windows 7, 8.1, RT 8.1, Windows 10 builds 1507 through 1809, and Windows Server 2008 through 2019. A local attacker who can already execute low-privileged code on a target machine can trigger the mishandled authentication handling with no user interaction and no special conditions (CVSS:3.1 AV:L/AC:L/PR:L/UI:N). Successful exploitation yields full control of the local system, with high confidentiality, integrity, and availability impact, so it is typically chained after an initial foothold such as phishing or malware. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-03-15 and notes known ransomware use; a public proof of concept is available (Exploit-DB 46156), and EPSS estimates a ~4.7% chance of exploitation in the next 30 days (91st percentile).
What to do: Apply Microsoft's January 2019 Patch Tuesday security updates (or any later cumulative update) across all affected Windows 7, 8.1, and 10 clients and Windows Server 2008-2019 hosts; organizations on Windows 7/Server 2008 R2 need Extended Security Update (ESU) coverage if still unpatched. Prioritize domain controllers, file servers, and internet-facing endpoints given the CISA KEV listing and known ransomware use, and since this is a post-foothold privilege escalation, also verify the initial-access vector (RCE/phishing) is remediated and monitor for local privilege-escalation activity.
| Microsoft Windows 10 | 1507, 1607, 1703, 1709, 1803, 1809 |
| Microsoft Windows 10 Servers | Server 2016, Server 2019, version 1709, version 1803 |
| Microsoft Windows 7 | — |
| Microsoft Windows 8.1 | all editions |
| Microsoft Windows RT 8.1 | all editions |
| Microsoft Windows Server 2008 | all editions |
| Microsoft Windows Server 2008 R2 | all editions |
| Microsoft Windows Server 2012 | all editions |
| Microsoft Windows Server 2012 R2 | all editions |
| Microsoft Windows Server 2016 | all editions |
| Microsoft Windows Server 2019 | all editions |
| Microsoft Windows Server (Semi-Annual Channel) | version 1709, version 1803 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka "Microsoft Windows Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows 7, windows 8.1, windows rt 8.1, windows server 1709, windows server 1803, windows server 2008
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H