CVE-2019-1215
KEV ransomwaremassLocal Privilege Escalation in Microsoft Windows Winsock Driver (ws2ifsl.sys)
CISA: Microsoft Windows Privilege Escalation Vulnerability
CVE-2019-1215 is an elevation-of-privilege vulnerability in ws2ifsl.sys, an auxiliary Winsock driver shipped with Windows, caused by improper handling of objects in memory (CWE-269). A local attacker with limited privileges can trigger the flaw via crafted requests to the driver, without user interaction, to execute code in kernel context. Successful exploitation grants elevated (SYSTEM-level) privileges, turning a low-privileged foothold into full control of the host and making the bug a useful link in ransomware attack chains. Affected systems include Windows 7, Windows 8.1, Windows RT 8.1, Windows 10 versions 1507 through 1903, and Windows Server versions 1803 and 1903. Microsoft patched the flaw in its October 2019 security updates; CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 with ransomware use known, and EPSS currently assigns a 19.3% probability of exploitation within 30 days (97th percentile).
What to do: Apply the Microsoft security update issued October 8, 2019 across all affected Windows 7, 8.1, RT 8.1, Windows 10 (1507-1903), and Server 1803/1903 systems, prioritizing hosts where ransomware operators could chain this local privilege escalation. Systems no longer receiving updates (Windows 7 without Extended Security Updates, Windows 10 versions past end of service) should be upgraded to a supported release. Organizations subject to CISA's KEV binding requirements must patch per the vendor instructions within the required deadline, and defenders should hunt legacy endpoints for prior exploitation given the known ransomware linkage.
| Microsoft Windows 10 | 1507, 1607, 1703, 1709, 1803, 1809, 1903 |
| Microsoft Windows 7 | — |
| Microsoft Windows 8.1 | — |
| Microsoft Windows RT 8.1 | all supported editions at time of disclosure |
| Microsoft Windows Server (Semi-Annual Channel) | 1803, 1903 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1253, CVE-2019-1278, CVE-2019-1303.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows 7, windows 8.1, windows rt 8.1, windows server 1803, windows server 1903
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H