ZeroHour

CVE-2019-0803

KEV ransomwaremass

Local Privilege Escalation in Microsoft Win32k Kernel Component

CISA: Microsoft Win32k Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
45%p99
Published
()
KEV added
AI analysis

CVE-2019-0803 is a privilege escalation flaw in Microsoft's Win32k kernel component caused by improper handling of objects in memory. It is triggered locally when code already running on a Windows system reaches the vulnerable Win32k object-handling path, allowing memory corruption that the attacker can leverage. Successful exploitation lets the attacker run arbitrary code in kernel mode, elevating from a low-privileged account to full system-level control. Per the available data, the affected component is Microsoft Win32k across Windows installations, though specific affected Windows versions and builds are not enumerated in the source data and should be confirmed against Microsoft's advisory. Exploitation is confirmed in the wild: CISA added it to the KEV catalog on 2021-11-03 with known ransomware use, and EPSS assigns a 45.2% probability of exploitation within 30 days (99th percentile).

What to do: Apply Microsoft Windows security updates per vendor instructions — this flaw was fixed in Microsoft's April 2019 security updates, so ensure systems are running those or later cumulative updates and verify by checking OS build numbers. Prioritize patching endpoints and servers where untrusted or low-privileged users can execute code, given documented ransomware chaining. Treat KEV status as a deadline: systems unpatched for this Win32k flaw should be considered actively targeted.

Affected
Microsoft Win32k
Estimated exposure
masshundreds of millions of Windows desktops and servers (Win32k is a core component shipped with essentially all Windows installations) — Win32k ships as a core kernel component in Windows client and server operating systems, so the potentially affected installed base is the entire Windows fleet; note that exploitation requires the attacker to already execute code locally,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0859.

CISA Known Exploited Vulnerability
Affected
Microsoft Win32k
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows 7, windows 8.1, windows rt 8.1, windows server 1709, windows server 1803, windows server 2008
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news