CVE-2019-1315
KEV ransomwaremassElevation of Privilege in Microsoft Windows Error Reporting Manager via Hard Link Abuse
CISA: Microsoft Windows Error Reporting Manager Privilege Escalation Vulnerability
Windows Error Reporting (WER) Manager improperly handles hard links (CWE-59, link following), allowing a local attacker with low privileges to redirect privileged file operations performed by the service. By planting a hard link that points at files WER operates on, the attacker can get the service to act on attacker-controlled content in a privileged context, with no user interaction required. Successful exploitation grants elevation of privilege on the local machine — commonly to SYSTEM — with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8, AV:L/PR:L). Users of Windows 7, 8.1, and RT 8.1, Windows 10 builds 1607 through 1903, and Windows Server 2008, 2012, and 2016 are affected; this issue is distinct from the related CVE-2019-1339 and CVE-2019-1342. The flaw was fixed in Microsoft's October 2019 Patch Tuesday and was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-15 with known ransomware use, so it is being exploited in the wild even though no public proof-of-concept is known.
What to do: Apply Microsoft's October 2019 Patch Tuesday security updates on all affected Windows 7/8.1/10 clients and Windows Server 2008/2012/2016 hosts via Windows Update, WSUS, or SCCM, as required by the CISA KEV catalog. Because CISA reports ransomware operators exploiting this flaw, prioritize domain-joined and internet-reachable servers and verify patch compliance across the estate, focusing on hosts where non-admin users can log on locally. If patching must be delayed, restrict interactive logon rights to trusted low-privilege users, since exploitation requires local access.
| Microsoft Windows 10 | 1607, 1703, 1709, 1803, 1809, 1903 |
| Microsoft Windows 7 | all supported editions at disclosure (October 2019) |
| Microsoft Windows 8.1 | all supported editions at disclosure (October 2019) |
| Microsoft Windows RT 8.1 | all supported editions at disclosure (October 2019) |
| Microsoft Windows Server 2008 | all supported editions at disclosure (October 2019) |
| Microsoft Windows Server 2012 | all supported editions at disclosure (October 2019) |
| Microsoft Windows Server 2016 | all supported editions at disclosure (October 2019) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1339, CVE-2019-1342.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows server 2016
- Weakness
- CWE-59
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H