ZeroHour

CVE-2019-0543

KEV ransomware PoC mass

Local Privilege Escalation (Improper Authentication) in Windows 7/8.1/10 and Server

CISA: Microsoft Windows Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
5%p91
Published
()
KEV added
AI analysis

CVE-2019-0543 is an elevation-of-privilege flaw (CWE-287, improper authentication) that exists when Windows improperly handles authentication requests, affecting Windows 7, 8.1, RT 8.1, Windows 10 builds 1507 through 1809, and Windows Server 2008 through 2019. A local attacker who can already execute low-privileged code on a target machine can trigger the mishandled authentication handling with no user interaction and no special conditions (CVSS:3.1 AV:L/AC:L/PR:L/UI:N). Successful exploitation yields full control of the local system, with high confidentiality, integrity, and availability impact, so it is typically chained after an initial foothold such as phishing or malware. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-03-15 and notes known ransomware use; a public proof of concept is available (Exploit-DB 46156), and EPSS estimates a ~4.7% chance of exploitation in the next 30 days (91st percentile).

What to do: Apply Microsoft's January 2019 Patch Tuesday security updates (or any later cumulative update) across all affected Windows 7, 8.1, and 10 clients and Windows Server 2008-2019 hosts; organizations on Windows 7/Server 2008 R2 need Extended Security Update (ESU) coverage if still unpatched. Prioritize domain controllers, file servers, and internet-facing endpoints given the CISA KEV listing and known ransomware use, and since this is a post-foothold privilege escalation, also verify the initial-access vector (RCE/phishing) is remediated and monitor for local privilege-escalation activity.

Affected
Microsoft Windows 101507, 1607, 1703, 1709, 1803, 1809
Microsoft Windows 10 ServersServer 2016, Server 2019, version 1709, version 1803
Microsoft Windows 7
Microsoft Windows 8.1all editions
Microsoft Windows RT 8.1all editions
Microsoft Windows Server 2008all editions
Microsoft Windows Server 2008 R2all editions
Microsoft Windows Server 2012all editions
Microsoft Windows Server 2012 R2all editions
Microsoft Windows Server 2016all editions
Microsoft Windows Server 2019all editions
Microsoft Windows Server (Semi-Annual Channel)version 1709, version 1803
Estimated exposure
masshundreds of millions of devices (~10^8-10^9): effectively every Windows 7/8.1/10 client or Windows Server 2008-2019 host that lacked the January 2019 updates — At disclosure Windows 10 had roughly 800 million active devices and Windows 7 still held on the order of a third of desktop share, and Windows Server is deployed at essentially every enterprise, so any system not yet running the January…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka "Microsoft Windows Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows 7, windows 8.1, windows rt 8.1, windows server 1709, windows server 1803, windows server 2008
Weakness
CWE-287
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news