CVE-2019-1322
KEV ransomware PoC massLocal Privilege Escalation in Microsoft Windows 10 and Windows Server
CISA: Microsoft Windows Privilege Escalation Vulnerability
CVE-2019-1322 is an elevation of privilege vulnerability in Microsoft Windows caused by improper handling of authentication requests. A local attacker with low privileges can trigger the flaw via crafted authentication requests with no user interaction required, gaining elevated (SYSTEM-level) rights and full confidentiality, integrity, and availability impact on the host. Affected products are Windows 10 versions 1803, 1809, and 1903, and Windows Server 1803, 1903, and 2019. The flaw is known to be exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-15 with ransomware use explicitly noted, and a public proof-of-concept exists. Because it is a local escalation, it is typically used as a post-compromise step to deepen an attacker's foothold, commonly as part of ransomware chains.
What to do: Apply Microsoft's current cumulative security updates to Windows 10 1803/1809/1903 and Windows Server 1803/1903/2019 per CISA's required action, and prioritize these systems given their KEV listing and known ransomware use. Because exploitation requires a low-privileged local foothold, also limit unprivileged local logon and RDP access on servers while patching. Verify hosts no longer run the affected builds before considering them remediated.
| Microsoft Windows 10 | 1803 |
| Microsoft Windows 10 | 1809 |
| Microsoft Windows 10 | 1903 |
| Microsoft Windows Server 1803 | all affected builds |
| Microsoft Windows Server 1903 | all affected builds |
| Microsoft Windows Server 2019 | all affected builds |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1320, CVE-2019-1340.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1803, windows 10 1809, windows 10 1903, windows server 1803, windows server 1903, windows server 2019
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H