ZeroHour

CVE-2019-1322

KEV ransomware PoC mass

Local Privilege Escalation in Microsoft Windows 10 and Windows Server

CISA: Microsoft Windows Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
19%p97
Published
()
KEV added
AI analysis

CVE-2019-1322 is an elevation of privilege vulnerability in Microsoft Windows caused by improper handling of authentication requests. A local attacker with low privileges can trigger the flaw via crafted authentication requests with no user interaction required, gaining elevated (SYSTEM-level) rights and full confidentiality, integrity, and availability impact on the host. Affected products are Windows 10 versions 1803, 1809, and 1903, and Windows Server 1803, 1903, and 2019. The flaw is known to be exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-15 with ransomware use explicitly noted, and a public proof-of-concept exists. Because it is a local escalation, it is typically used as a post-compromise step to deepen an attacker's foothold, commonly as part of ransomware chains.

What to do: Apply Microsoft's current cumulative security updates to Windows 10 1803/1809/1903 and Windows Server 1803/1903/2019 per CISA's required action, and prioritize these systems given their KEV listing and known ransomware use. Because exploitation requires a low-privileged local foothold, also limit unprivileged local logon and RDP access on servers while patching. Verify hosts no longer run the affected builds before considering them remediated.

Affected
Microsoft Windows 101803
Microsoft Windows 101809
Microsoft Windows 101903
Microsoft Windows Server 1803all affected builds
Microsoft Windows Server 1903all affected builds
Microsoft Windows Server 2019all affected builds
Estimated exposure
masstens of millions of Windows 10/Server endpoints on unpatched 1803–1903-era builds (Windows 10 installed base was hundreds of millions of devices at disclosure;… — Windows 10 releases 1803, 1809, and 1903 collectively made up a large share of the roughly 900-million-device Windows 10 installed base at the time of disclosure, and Windows Server 2019 is a widely deployed datacenter release, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1320, CVE-2019-1340.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1803, windows 10 1809, windows 10 1903, windows server 1803, windows server 1903, windows server 2019
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news