Executive brief
An elevation of privilege vulnerability exists in Microsoft Windows when the operating system improperly handles authentication requests. A local attacker who successfully exploits this vulnerability could run processes in an elevated context.
Affected products
- Microsoft Windows 7
- Microsoft Windows 8.1
- Microsoft Windows RT 8.1
- Microsoft Windows 10
- Microsoft Windows Server 2008
- Microsoft Windows Server 2008 R2
- Microsoft Windows Server 2012
- Microsoft Windows Server 2012 R2
- Microsoft Windows Server 2016
- Microsoft Windows Server 2019
Timeline
- 2019-01-08: disclosed: Initial disclosure date based on MSRC/SecurityFocus records.
- 2022-03-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2022-03-15: exploited: Confirmed as exploited in the wild.