ZeroHour

CVE-2019-1458

KEV ransomware PoC ×2mass

Win32k Object-Handling Flaw Enables Local Privilege Escalation in Microsoft Windows

CISA: Microsoft Win32k Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
74%p99
Published
()
KEV added
AI analysis

An elevation of privilege vulnerability exists in the Windows kernel's Win32k component, which fails to properly handle objects in memory (an uninitialized-variable condition). A local attacker who can already execute limited code on a target machine can trigger the flaw to gain kernel-level execution and elevate to SYSTEM privileges, giving full control of the host. Affected platforms are Windows 7, Windows 8.1, Windows RT 8.1, Windows 10 1507 and 1607, and Windows Server 2008, 2012 and 2016. The bug was patched in Microsoft's December 2019 Patch Tuesday after being actively exploited as a zero-day, including in the WizardOpium campaign attributed to a North Korea-linked actor. It is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-01-10, with known ransomware use) and carries a high EPSS of 74.3%.

What to do: Apply the December 2019 security updates (or later cumulative updates) from Microsoft per CISA's required action. Because Windows 7/8.1 and Server 2008/2012 are past end of support and Server 2016 support is winding down, prioritize migration to supported Windows versions. Hunt for signs of local privilege escalation and follow-on activity, since this bug was used as a zero-day and appears in ransomware attack chains.

Affected
microsoft windows 10 1507all supported editions at time of patch (December 2019)
microsoft windows 10 1607all supported editions at time of patch (December 2019)
microsoft windows 7all supported editions
microsoft windows 8.1all supported editions
microsoft windows rt 8.1all supported editions
microsoft windows server 2008all supported editions
microsoft windows server 2012all supported editions
microsoft windows server 2016all supported editions
Estimated exposure
masshundreds of millions of devices (Windows 7 alone held roughly a third of desktop market share at disclosure; millions of Server 2008/2012/2016 hosts remain… — The affected set includes Windows 7/8.1 and Server 2008-2016, which together accounted for a very large share of the global Windows installed base when this was patched in December 2019, so the plausibly affected population is on the order…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

CISA Known Exploited Vulnerability
Affected
Microsoft Win32k
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012, windows server 2016
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news