CVE-2019-1388
KEV ransomwaremassLocal Privilege Escalation in Microsoft Windows Certificate Dialog (CVE-2019-1388)
CISA: Microsoft Windows Certificate Dialog Privilege Escalation Vulnerability
CVE-2019-1388 is an elevation-of-privilege vulnerability in the Windows Certificate Dialog that fails to properly enforce user privileges (CWE-269). An attacker who can already run code or open crafted certificate content on a local machine can trigger the vulnerable dialog and cause privileged components to execute attacker-chosen actions without proper privilege checks. Successful exploitation yields high-impact control of confidentiality, integrity, and availability, effectively a full SYSTEM-level compromise of the host. Essentially every Windows client and server release in service at disclosure is affected, including Windows 7, 8.1 and RT 8.1, Windows 10 versions 1507 through 1903, and Windows Server 2008, 2012 and 1903. The flaw was fixed in Microsoft's November 2019 security updates, but CISA added it to the Known Exploited Vulnerabilities catalog on 2023-04-07 with known ransomware use, and EPSS currently estimates an 8.6% probability of exploitation within 30 days (95th percentile).
What to do: Apply Microsoft security updates (November 2019 cumulative updates or later) to all in-scope Windows 7, 8.1, 10, RT 8.1 and Server 2008/2012/1903 systems, prioritizing hosts where unprivileged users can log on, per the KEV required action. For legacy releases past mainstream support, confirm Extended Security Update (ESU) coverage or plan migration, and verify installed patch levels via the OS build number. Because CISA notes known ransomware use, review incident timelines and endpooint logs for local-privilege-escalation activity preceding ransomware deployment.
| microsoft windows 10 1507 | — |
| microsoft windows 10 1607 | affected builds as listed by Microsoft; fixed in November 2019 security updates |
| microsoft windows 10 1709 | affected builds as listed by Microsoft; fixed in November 2019 security updates |
| microsoft windows 10 1803 | affected builds as listed by Microsoft; fixed in November 2019 security updates |
| microsoft windows 10 1809 | affected builds as listed by Microsoft; fixed in November 2019 security updates |
| microsoft windows 10 1903 | affected builds as listed by Microsoft; fixed in November 2019 security updates |
| microsoft windows 7 | all supported editions at disclosure; fixed in November 2019 security updates |
| microsoft windows 8.1 | all supported editions at disclosure; fixed in November 2019 security updates |
| microsoft windows rt 8.1 | all supported editions at disclosure; fixed in November 2019 security updates |
| microsoft windows server 1903 | affected builds as listed by Microsoft; fixed in November 2019 security updates |
| microsoft windows server 2008 | affected editions (including R2 SKUs per CPE listing); fixed in November 2019 security updates |
| microsoft windows server 2012 | affected editions (including R2 SKUs per CPE listing); fixed in November 2019 security updates |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Certificate Dialog Elevation of Privilege Vulnerability'.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows 7, windows 8.1, windows rt 8.1, windows server 1903, windows server 2008, windows server 2012
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H