Junglewise Threat Intelligence

CVE-2019-0797: Microsoft Win32k Privilege Escalation Vulnerability

CVE-2019-0797 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Windows Server 2016, Microsoft Windows 8.1, Microsoft Windows Server 2019, Microsoft Win32K, Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows Rt 8.1. Vendors: Microsoft.

Executive brief

An elevation of privilege vulnerability exists in the Windows Win32k component due to improper handling of objects in memory. A local attacker who successfully exploits this vulnerability could execute arbitrary code in kernel mode, granting them full control over the affected system.

Affected products

  • Microsoft Windows 10 1507, 1607, 1703, 1709, 1803, 1809
  • Microsoft Windows 8.1
  • Microsoft Windows RT 8.1
  • Microsoft Windows Server 2012 R2
  • Microsoft Windows Server 2016 1709, 1803
  • Microsoft Windows Server 2019

Timeline

  • 2019-04-09: disclosed: Initial analysis by NIST
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats