ZeroHour

CVE-2019-1388

KEV ransomwaremass

Local Privilege Escalation in Microsoft Windows Certificate Dialog (CVE-2019-1388)

CISA: Microsoft Windows Certificate Dialog Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
9%p95
Published
()
KEV added
AI analysis

CVE-2019-1388 is an elevation-of-privilege vulnerability in the Windows Certificate Dialog that fails to properly enforce user privileges (CWE-269). An attacker who can already run code or open crafted certificate content on a local machine can trigger the vulnerable dialog and cause privileged components to execute attacker-chosen actions without proper privilege checks. Successful exploitation yields high-impact control of confidentiality, integrity, and availability, effectively a full SYSTEM-level compromise of the host. Essentially every Windows client and server release in service at disclosure is affected, including Windows 7, 8.1 and RT 8.1, Windows 10 versions 1507 through 1903, and Windows Server 2008, 2012 and 1903. The flaw was fixed in Microsoft's November 2019 security updates, but CISA added it to the Known Exploited Vulnerabilities catalog on 2023-04-07 with known ransomware use, and EPSS currently estimates an 8.6% probability of exploitation within 30 days (95th percentile).

What to do: Apply Microsoft security updates (November 2019 cumulative updates or later) to all in-scope Windows 7, 8.1, 10, RT 8.1 and Server 2008/2012/1903 systems, prioritizing hosts where unprivileged users can log on, per the KEV required action. For legacy releases past mainstream support, confirm Extended Security Update (ESU) coverage or plan migration, and verify installed patch levels via the OS build number. Because CISA notes known ransomware use, review incident timelines and endpooint logs for local-privilege-escalation activity preceding ransomware deployment.

Affected
microsoft windows 10 1507
microsoft windows 10 1607affected builds as listed by Microsoft; fixed in November 2019 security updates
microsoft windows 10 1709affected builds as listed by Microsoft; fixed in November 2019 security updates
microsoft windows 10 1803affected builds as listed by Microsoft; fixed in November 2019 security updates
microsoft windows 10 1809affected builds as listed by Microsoft; fixed in November 2019 security updates
microsoft windows 10 1903affected builds as listed by Microsoft; fixed in November 2019 security updates
microsoft windows 7all supported editions at disclosure; fixed in November 2019 security updates
microsoft windows 8.1all supported editions at disclosure; fixed in November 2019 security updates
microsoft windows rt 8.1all supported editions at disclosure; fixed in November 2019 security updates
microsoft windows server 1903affected builds as listed by Microsoft; fixed in November 2019 security updates
microsoft windows server 2008affected editions (including R2 SKUs per CPE listing); fixed in November 2019 security updates
microsoft windows server 2012affected editions (including R2 SKUs per CPE listing); fixed in November 2019 security updates
Estimated exposure
masshundreds of millions of Windows endpoints and servers (the affected release list covered nearly the entire Windows installed base at the time of disclosure) — Windows' dominant desktop and server market share means the affected versions (Windows 7/8.1/10 client and 2008/2012/1903 server) spaned essentially all corporate and consumer Windows deployments in 2019, putting exposure in the hundreds…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Certificate Dialog Elevation of Privilege Vulnerability'.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows 7, windows 8.1, windows rt 8.1, windows server 1903, windows server 2008, windows server 2012
Weakness
CWE-269
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news