CVE-2019-0797
KEVmassWin32k Elevation of Privilege in Microsoft Windows (Exploited as Zero-Day)
CISA: Microsoft Win32k Privilege Escalation Vulnerability
CVE-2019-0797 is an elevation of privilege flaw in the Windows Win32k kernel component, which fails to properly handle objects in memory. A local attacker who can already execute code on an affected machine can trigger the bug with a specially crafted application and escalate from a low-privileged user account to SYSTEM-level privileges, gaining full control of the host; this flaw is distinct from the related CVE-2019-0808 fixed the same month. Any system running an affected Windows release is exposed: Windows 10 versions 1507 through 1809, Windows 8.1 and RT 8.1, and Windows Server 2012, 2016, 1709 and 1803. The bug was a zero-day when Microsoft patched it in March 2019, having been used in targeted attacks attributed to the FruityArmor and SandCat groups, and it is listed in CISA's Known Exploited Vulnerabilities catalog, so in-the-wild exploitation is confirmed even though no public proof-of-concept is known.
What to do: Apply Microsoft's March 2019 cumulative updates (or monthly rollups for Windows 8.1/RT 8.1 and Server 2012) on every affected Windows 10, 8.1, and Server build, and confirm installation by checking the OS build/update level via winver or systeminfo. Because the flaw was used as a zero-day by FruityArmor and SandCat in targeted attacks, review endpoint telemetry for signs of those campaigns and treat the CISA KEV patching requirement as binding. Prioritize systems where low-privileged users run untrusted code, since exploitation requires only local code execution and then yields full SYSTEM-level control.
| Microsoft Windows 10 1507 | all builds prior to the March 2019 security updates |
| Microsoft Windows 10 1607 | all builds prior to the March 2019 security updates |
| Microsoft Windows 10 1703 | all builds prior to the March 2019 security updates |
| Microsoft Windows 10 1709 | all builds prior to the March 2019 security updates |
| Microsoft Windows 10 1803 | all builds prior to the March 2019 security updates |
| Microsoft Windows 10 1809 | all builds prior to the March 2019 security updates |
| Microsoft Windows 8.1 | all builds prior to the March 2019 security updates |
| Microsoft Windows RT 8.1 | all builds prior to the March 2019 security updates |
| Microsoft Windows Server, version 1709 | all builds prior to the March 2019 security updates |
| Microsoft Windows Server, version 1803 | all builds prior to the March 2019 security updates |
| Microsoft Windows Server 2012 | all builds prior to the March 2019 monthly rollup security updates |
| Microsoft Windows Server 2016 | all builds prior to the March 2019 security updates |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0808.
- Affected
- Microsoft Win32k
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows 8.1, windows rt 8.1, windows server 1709, windows server 1803, windows server 2012, windows server 2016
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H