CVE-2019-0859
KEV ransomwaremass1Local Privilege Escalation in Microsoft Win32k on Windows
CISA: Microsoft Win32k Privilege Escalation Vulnerability
CVE-2019-0859 is an elevation of privilege vulnerability in the Win32k kernel component of Microsoft Windows, caused by the component failing to properly handle objects in memory. It is exploited locally: a low-privileged user or process already running on the machine can trigger the mishandling with no user interaction required, per the CVSS vector (AV:L/PR:L/UI:N). Successful exploitation elevates the attacker to kernel privileges, with high impact to confidentiality, integrity and availability, typically used to break out of user-level restrictions after an initial foothold. Any unpatched Windows 7, 8.1, RT 8.1, Windows 10 versions 1507 through 1809, or Windows Server 2008, 1709, or 1803 system is affected; the flaw was fixed in Microsoft's April 2019 security updates. It was reported as actively exploited when patched, was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use, and carries an EPSS of 4.2% (90th percentile); no public PoC is known.
What to do: Apply Microsoft's April 2019 (or later) Windows security updates to all affected Windows 7, 8.1, RT 8.1, Windows 10 1507–1809, and Windows Server 2008/1709/1803 systems, per CISA's required action. Prioritize user-facing and shared systems (workstations, RDS/terminal servers, jump hosts) where an attacker is most likely to gain a local foothold, and verify patch levels through your update-management tooling.
| Microsoft Windows 10 | 1507, 1607, 1703, 1709, 1803, 1809 |
| Microsoft Windows 7 | — |
| Microsoft Windows 8.1 | — |
| Microsoft Windows RT 8.1 | — |
| Microsoft Windows Server 1709 | — |
| Microsoft Windows Server 1803 | — |
| Microsoft Windows Server 2008 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0803.
- Affected
- Microsoft Win32k
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows 7, windows 8.1, windows rt 8.1, windows server 1709, windows server 1803, windows server 2008
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H