CVE-2019-1458
KEV ransomware PoC ×2massWin32k Object-Handling Flaw Enables Local Privilege Escalation in Microsoft Windows
CISA: Microsoft Win32k Privilege Escalation Vulnerability
An elevation of privilege vulnerability exists in the Windows kernel's Win32k component, which fails to properly handle objects in memory (an uninitialized-variable condition). A local attacker who can already execute limited code on a target machine can trigger the flaw to gain kernel-level execution and elevate to SYSTEM privileges, giving full control of the host. Affected platforms are Windows 7, Windows 8.1, Windows RT 8.1, Windows 10 1507 and 1607, and Windows Server 2008, 2012 and 2016. The bug was patched in Microsoft's December 2019 Patch Tuesday after being actively exploited as a zero-day, including in the WizardOpium campaign attributed to a North Korea-linked actor. It is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-01-10, with known ransomware use) and carries a high EPSS of 74.3%.
What to do: Apply the December 2019 security updates (or later cumulative updates) from Microsoft per CISA's required action. Because Windows 7/8.1 and Server 2008/2012 are past end of support and Server 2016 support is winding down, prioritize migration to supported Windows versions. Hunt for signs of local privilege escalation and follow-on activity, since this bug was used as a zero-day and appears in ransomware attack chains.
| microsoft windows 10 1507 | all supported editions at time of patch (December 2019) |
| microsoft windows 10 1607 | all supported editions at time of patch (December 2019) |
| microsoft windows 7 | all supported editions |
| microsoft windows 8.1 | all supported editions |
| microsoft windows rt 8.1 | all supported editions |
| microsoft windows server 2008 | all supported editions |
| microsoft windows server 2012 | all supported editions |
| microsoft windows server 2016 | all supported editions |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
- Affected
- Microsoft Win32k
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows server 2016
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H