CVE-2019-0808
KEV PoC mass1· 2 readsLocal Privilege Escalation in Microsoft Win32k on Windows 7 and Server 2008
CISA: Microsoft Win32k Privilege Escalation Vulnerability
CVE-2019-0808 is an elevation-of-privilege flaw in the Windows Win32k kernel component, which fails to properly handle objects in memory, allowing a local, low-privileged attacker to execute code in the kernel and take full control of the system (CVSS 3.1: 7.8, high impact on confidentiality, integrity and availability). It is triggered by a local attacker running crafted actions against vulnerable Win32k system calls; a public proof of concept based on the NtUserMNDragOver call path is available. Per the source data, affected products are Windows 7 and Windows Server 2008 (exact service-pack/version ranges are not specified in the data). The bug was one of two Win32k zero-days patched in the March 2019 Patch Tuesday, was being actively exploited in targeted attacks attributed to the FruityArmor and SandCat groups, and Microsoft followed with an out-of-band fix after Google disclosed the zero-day. It is listed in CISA KEV (added 2021-11-03, ransomware use unknown), and EPSS currently assigns roughly a 53% probability of exploitation within 30 days (99th percentile).
What to do: Apply the March 2019 Microsoft security updates (or the out-of-band fix) for Windows 7 and Windows Server 2008, including Extended Security Updates for systems past the January 2020 end of support, per the CISA KEV required action. Prioritize shared/terminal and RDS hosts where low-privileged users log in, since successful exploitation grants kernel-level privileges, and review those systems for indicators of the FruityArmor/SandCat targeted intrusions. No reliable workaround is documented for this Win32k flaw, so patching is the primary mitigation.
| Microsoft Windows 7 | — |
| Microsoft Windows Server 2008 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0797.
- Affected
- Microsoft Win32k
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 7, windows server 2008
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H