CVE-2019-1132
KEVmassLocal Privilege Escalation in Microsoft Win32k on Windows 7 and Server 2008
CISA: Microsoft Win32k Privilege Escalation Vulnerability
CVE-2019-1132 is an elevation of privilege flaw in the Windows kernel-mode Win32k component, which fails to properly handle objects in memory. It is triggered locally: an attacker who can already run low-privileged code on a target machine exploits the faulty object handling to execute code in the kernel with SYSTEM privileges, with no user interaction required. A successful exploit yields full control of the host, making this a typical second stage chained behind a remote code execution bug or a malware foothold. Only Windows 7 and Windows Server 2008 systems missing the vendor fix are affected. Exploitation is confirmed in the wild — CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-03-15 — though no public proof-of-concept is known and ransomware involvement is unknown; EPSS puts 30-day exploitation odds around 10% (95th percentile).
What to do: Apply the July 2019 (or later, including final pre-EOL) Win32k security updates for Windows 7 and Windows Server 2008, prioritizing hosts on the CISA KEV remediation timeline; since both platforms are past end of support, plan migration to a supported Windows release. As interim mitigation, restrict untrusted local code execution, and verify patch status of win32k across your estate using patch-management inventory, as exploited-in-the-wild KEV status makes unpatched legacy hosts high-priority targets.
| Microsoft Windows 7 | all editions in scope of the vendor advisory (fixed by the July 2019 Win32k security updates) |
| Microsoft Windows Server 2008 | all editions in scope of the vendor advisory (fixed by the July 2019 Win32k security updates) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
- Affected
- Microsoft Win32k
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 7, windows server 2008
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H