ZeroHour

CVE-2019-1132

KEVmass

Local Privilege Escalation in Microsoft Win32k on Windows 7 and Server 2008

CISA: Microsoft Win32k Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
10%p95
Published
()
KEV added
AI analysis

CVE-2019-1132 is an elevation of privilege flaw in the Windows kernel-mode Win32k component, which fails to properly handle objects in memory. It is triggered locally: an attacker who can already run low-privileged code on a target machine exploits the faulty object handling to execute code in the kernel with SYSTEM privileges, with no user interaction required. A successful exploit yields full control of the host, making this a typical second stage chained behind a remote code execution bug or a malware foothold. Only Windows 7 and Windows Server 2008 systems missing the vendor fix are affected. Exploitation is confirmed in the wild — CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-03-15 — though no public proof-of-concept is known and ransomware involvement is unknown; EPSS puts 30-day exploitation odds around 10% (95th percentile).

What to do: Apply the July 2019 (or later, including final pre-EOL) Win32k security updates for Windows 7 and Windows Server 2008, prioritizing hosts on the CISA KEV remediation timeline; since both platforms are past end of support, plan migration to a supported Windows release. As interim mitigation, restrict untrusted local code execution, and verify patch status of win32k across your estate using patch-management inventory, as exploited-in-the-wild KEV status makes unpatched legacy hosts high-priority targets.

Affected
Microsoft Windows 7all editions in scope of the vendor advisory (fixed by the July 2019 Win32k security updates)
Microsoft Windows Server 2008all editions in scope of the vendor advisory (fixed by the July 2019 Win32k security updates)
Estimated exposure
masswell over 1 million systems — plausibly tens of millions of legacy Windows 7 / Server 2008 machines, of which the unpatched share is exposed — Windows 7 alone had an installed base in the hundreds of millions when the fix shipped in July 2019, and tens of millions of Windows 7 and Windows Server 2008 machines were still running when CISA added this CVE to KEV in 2022, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

CISA Known Exploited Vulnerability
Affected
Microsoft Win32k
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 7, windows server 2008
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news