ZeroHour

CVE-2019-0863

KEVmass

Local Privilege Escalation Flaw in Microsoft Windows Error Reporting (WER)

CISA: Microsoft Windows Error Reporting (WER) Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
5%p92
Published
()
KEV added
AI analysis

CVE-2019-0863 is an elevation of privilege vulnerability in Microsoft Windows Error Reporting (WER), caused by the way WER handles files on affected Windows releases. A local attacker who can already execute code on a vulnerable machine with limited privileges can trigger the flaw without user interaction and gain higher local privileges, with high impact on confidentiality, integrity, and availability per the CVSS vector. Anyone running the listed releases is affected: Windows 10 versions 1507 through 1903, Windows 7, Windows 8.1, Windows RT 8.1, and Windows Server versions 1803 and 1903; systems current on Microsoft's security updates are not vulnerable. The flaw is confirmed exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 (ransomware association unknown) — although no public proof-of-concept is known, and EPSS puts the 30-day exploitation probability at 5.2% (92nd percentile). The required action per CISA is to apply updates per vendor instructions.

What to do: Apply Microsoft's security updates for each affected release as the CISA KEV entry requires; the flaw was fixed in 2019 cumulative updates, so any system current on monthly servicing is already protected. Prioritize patching multi-user and remote-access systems (RDS/VDI hosts, jump boxes, shared workstations) where low-privileged users can run code and escalate, and migrate unpatched Windows 7/8.1/RT 8.1 machines — many now past end of support — to a supported, patched Windows release.

Affected
microsoft Windows 101507, 1607, 1703, 1709, 1803, 1809, 1903
microsoft Windows 7
microsoft Windows 8.1
microsoft Windows RT 8.1
microsoft Windows Serverversion 1803
microsoft Windows Serverversion 1903
Estimated exposure
masshundreds of thousands to millions of currently unpatched Windows endpoints (affected releases once ran on hundreds of millions of devices) — Microsoft reported Windows 10 alone on roughly 900 million devices in this era, with Windows 7 still on hundreds of millions of PCs, so the theoretical affected installed base is in the hundreds of millions; since the fix shipped in 2019…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows 7, windows 8.1, windows rt 8.1, windows server 1803, windows server 1903
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news