ZeroHour

CVE-2019-1315

KEV ransomwaremass

Elevation of Privilege in Microsoft Windows Error Reporting Manager via Hard Link Abuse

CISA: Microsoft Windows Error Reporting Manager Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
3%p88
Published
()
KEV added
AI analysis

Windows Error Reporting (WER) Manager improperly handles hard links (CWE-59, link following), allowing a local attacker with low privileges to redirect privileged file operations performed by the service. By planting a hard link that points at files WER operates on, the attacker can get the service to act on attacker-controlled content in a privileged context, with no user interaction required. Successful exploitation grants elevation of privilege on the local machine — commonly to SYSTEM — with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8, AV:L/PR:L). Users of Windows 7, 8.1, and RT 8.1, Windows 10 builds 1607 through 1903, and Windows Server 2008, 2012, and 2016 are affected; this issue is distinct from the related CVE-2019-1339 and CVE-2019-1342. The flaw was fixed in Microsoft's October 2019 Patch Tuesday and was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-15 with known ransomware use, so it is being exploited in the wild even though no public proof-of-concept is known.

What to do: Apply Microsoft's October 2019 Patch Tuesday security updates on all affected Windows 7/8.1/10 clients and Windows Server 2008/2012/2016 hosts via Windows Update, WSUS, or SCCM, as required by the CISA KEV catalog. Because CISA reports ransomware operators exploiting this flaw, prioritize domain-joined and internet-reachable servers and verify patch compliance across the estate, focusing on hosts where non-admin users can log on locally. If patching must be delayed, restrict interactive logon rights to trusted low-privilege users, since exploitation requires local access.

Affected
Microsoft Windows 101607, 1703, 1709, 1803, 1809, 1903
Microsoft Windows 7all supported editions at disclosure (October 2019)
Microsoft Windows 8.1all supported editions at disclosure (October 2019)
Microsoft Windows RT 8.1all supported editions at disclosure (October 2019)
Microsoft Windows Server 2008all supported editions at disclosure (October 2019)
Microsoft Windows Server 2012all supported editions at disclosure (October 2019)
Microsoft Windows Server 2016all supported editions at disclosure (October 2019)
Estimated exposure
mass≈1 billion Windows devices (affected versions spanned nearly the entire Windows installed base at the October 2019 fix) — The affected list covers Windows 7, 8.1, RT 8.1, six Windows 10 servicing releases, and Windows Server 2008/2012/2016, which together represented essentially the whole Windows installed base — on the order of a billion or more devices —…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1339, CVE-2019-1342.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows server 2016
Weakness
CWE-59
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news