CVE-2019-0863
KEVmassLocal Privilege Escalation Flaw in Microsoft Windows Error Reporting (WER)
CISA: Microsoft Windows Error Reporting (WER) Privilege Escalation Vulnerability
CVE-2019-0863 is an elevation of privilege vulnerability in Microsoft Windows Error Reporting (WER), caused by the way WER handles files on affected Windows releases. A local attacker who can already execute code on a vulnerable machine with limited privileges can trigger the flaw without user interaction and gain higher local privileges, with high impact on confidentiality, integrity, and availability per the CVSS vector. Anyone running the listed releases is affected: Windows 10 versions 1507 through 1903, Windows 7, Windows 8.1, Windows RT 8.1, and Windows Server versions 1803 and 1903; systems current on Microsoft's security updates are not vulnerable. The flaw is confirmed exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 (ransomware association unknown) — although no public proof-of-concept is known, and EPSS puts the 30-day exploitation probability at 5.2% (92nd percentile). The required action per CISA is to apply updates per vendor instructions.
What to do: Apply Microsoft's security updates for each affected release as the CISA KEV entry requires; the flaw was fixed in 2019 cumulative updates, so any system current on monthly servicing is already protected. Prioritize patching multi-user and remote-access systems (RDS/VDI hosts, jump boxes, shared workstations) where low-privileged users can run code and escalate, and migrate unpatched Windows 7/8.1/RT 8.1 machines — many now past end of support — to a supported, patched Windows release.
| microsoft Windows 10 | 1507, 1607, 1703, 1709, 1803, 1809, 1903 |
| microsoft Windows 7 | — |
| microsoft Windows 8.1 | — |
| microsoft Windows RT 8.1 | — |
| microsoft Windows Server | version 1803 |
| microsoft Windows Server | version 1903 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows 7, windows 8.1, windows rt 8.1, windows server 1803, windows server 1903
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H