ZeroHour

CVE-2019-0797

KEVmass

Win32k Elevation of Privilege in Microsoft Windows (Exploited as Zero-Day)

CISA: Microsoft Win32k Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
2%p78
Published
()
KEV added
AI analysis

CVE-2019-0797 is an elevation of privilege flaw in the Windows Win32k kernel component, which fails to properly handle objects in memory. A local attacker who can already execute code on an affected machine can trigger the bug with a specially crafted application and escalate from a low-privileged user account to SYSTEM-level privileges, gaining full control of the host; this flaw is distinct from the related CVE-2019-0808 fixed the same month. Any system running an affected Windows release is exposed: Windows 10 versions 1507 through 1809, Windows 8.1 and RT 8.1, and Windows Server 2012, 2016, 1709 and 1803. The bug was a zero-day when Microsoft patched it in March 2019, having been used in targeted attacks attributed to the FruityArmor and SandCat groups, and it is listed in CISA's Known Exploited Vulnerabilities catalog, so in-the-wild exploitation is confirmed even though no public proof-of-concept is known.

What to do: Apply Microsoft's March 2019 cumulative updates (or monthly rollups for Windows 8.1/RT 8.1 and Server 2012) on every affected Windows 10, 8.1, and Server build, and confirm installation by checking the OS build/update level via winver or systeminfo. Because the flaw was used as a zero-day by FruityArmor and SandCat in targeted attacks, review endpoint telemetry for signs of those campaigns and treat the CISA KEV patching requirement as binding. Prioritize systems where low-privileged users run untrusted code, since exploitation requires only local code execution and then yields full SYSTEM-level control.

Affected
Microsoft Windows 10 1507all builds prior to the March 2019 security updates
Microsoft Windows 10 1607all builds prior to the March 2019 security updates
Microsoft Windows 10 1703all builds prior to the March 2019 security updates
Microsoft Windows 10 1709all builds prior to the March 2019 security updates
Microsoft Windows 10 1803all builds prior to the March 2019 security updates
Microsoft Windows 10 1809all builds prior to the March 2019 security updates
Microsoft Windows 8.1all builds prior to the March 2019 security updates
Microsoft Windows RT 8.1all builds prior to the March 2019 security updates
Microsoft Windows Server, version 1709all builds prior to the March 2019 security updates
Microsoft Windows Server, version 1803all builds prior to the March 2019 security updates
Microsoft Windows Server 2012all builds prior to the March 2019 monthly rollup security updates
Microsoft Windows Server 2016all builds prior to the March 2019 security updates
Estimated exposure
mass≈hundreds of millions of Windows devices (affected versions spanned nearly the entire Windows 10 installed base of roughly 800M devices, plus Windows 8.1/RT… — Microsoft reported roughly 800 million active Windows 10 devices in early 2019 and the affected range (1507 through 1809) covered essentially that entire install base, with additional volume from Windows 8.1/RT 8.1 clients and the listed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0808.

CISA Known Exploited Vulnerability
Affected
Microsoft Win32k
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows 8.1, windows rt 8.1, windows server 1709, windows server 1803, windows server 2012, windows server 2016
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news