ZeroHour

CVE-2019-0808

KEV PoC mass1· 2 reads

Local Privilege Escalation in Microsoft Win32k on Windows 7 and Server 2008

CISA: Microsoft Win32k Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
53%p99
Published
()
KEV added
AI analysis

CVE-2019-0808 is an elevation-of-privilege flaw in the Windows Win32k kernel component, which fails to properly handle objects in memory, allowing a local, low-privileged attacker to execute code in the kernel and take full control of the system (CVSS 3.1: 7.8, high impact on confidentiality, integrity and availability). It is triggered by a local attacker running crafted actions against vulnerable Win32k system calls; a public proof of concept based on the NtUserMNDragOver call path is available. Per the source data, affected products are Windows 7 and Windows Server 2008 (exact service-pack/version ranges are not specified in the data). The bug was one of two Win32k zero-days patched in the March 2019 Patch Tuesday, was being actively exploited in targeted attacks attributed to the FruityArmor and SandCat groups, and Microsoft followed with an out-of-band fix after Google disclosed the zero-day. It is listed in CISA KEV (added 2021-11-03, ransomware use unknown), and EPSS currently assigns roughly a 53% probability of exploitation within 30 days (99th percentile).

What to do: Apply the March 2019 Microsoft security updates (or the out-of-band fix) for Windows 7 and Windows Server 2008, including Extended Security Updates for systems past the January 2020 end of support, per the CISA KEV required action. Prioritize shared/terminal and RDS hosts where low-privileged users log in, since successful exploitation grants kernel-level privileges, and review those systems for indicators of the FruityArmor/SandCat targeted intrusions. No reliable workaround is documented for this Win32k flaw, so patching is the primary mitigation.

Affected
Microsoft Windows 7
Microsoft Windows Server 2008
Estimated exposure
massroughly 500 million+ Windows 7 / Windows Server 2008 installations (Windows 7 held ~40% desktop OS share in early 2019) — Windows 7 still ran on about four in ten Windows desktops when the flaw was patched in March 2019 and Windows Server 2008 remained widely deployed in enterprise estates, implying an installed base in the hundreds of millions; note this is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0797.

CISA Known Exploited Vulnerability
Affected
Microsoft Win32k
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 7, windows server 2008
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news