CVE-2019-0880
KEVmassLocal Privilege Escalation in Microsoft Windows splwow64.exe (CVE-2019-0880)
CISA: Microsoft Windows Privilege Escalation Vulnerability
CVE-2019-0880 is a local elevation of privilege (EoP) flaw in how splwow64.exe — the 64-bit Windows process used to let 32-bit applications print — handles certain calls. An attacker who can already execute low-privileged code on an affected system can trigger the flaw with no user interaction and gain elevated privileges, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8, AV:L/PR:L/UI:N). The affected list covers most of the Windows fleet of the era: Windows 10 versions 1507 through 1903, Windows 8.1, Windows RT 8.1, and Windows Server 2012, 2016, and version 1903. Microsoft shipped the fix in the July 2019 security updates, which related coverage tied to two actively exploited Windows zero-days, and CISA formally added the flaw to its Known Exploited Vulnerabilities catalog on 2022-05-23, confirming in-the-wild exploitation (ransomware association unknown). EPSS currently rates the 30-day exploitation probability at 2.3% (82nd percentile), so unpatched systems remain a realistic target.
What to do: Apply the Microsoft security updates released in July 2019, or any later cumulative updates, to all affected Windows 10, Windows 8.1, Windows RT 8.1, and Windows Server systems, per the CISA KEV required action. Because exploitation requires local low-privileged code execution, prioritize shared and multi-user systems such as RDS/terminal servers, shared workstations, and kiosks. Verify remediation against the KEV entry added 2022-05-23; no public PoC is known, and no ransomware association has been established.
| Microsoft Windows 10 | 1507, 1607, 1703, 1709, 1803, 1809, 1903 |
| Microsoft Windows 8.1 | 8.1 |
| Microsoft Windows RT 8.1 | RT 8.1 |
| Microsoft Windows Server 1903 | 1903 |
| Microsoft Windows Server 2012 | 2012 |
| Microsoft Windows Server 2016 | 2016 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows 8.1, windows rt 8.1, windows server 1903, windows server 2012, windows server 2016
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H