CVE-2019-1215: high-severity vulnerability in Microsoft Windows
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Apply updates per vendor instructions.
A flaw in Windows' network driver (ws2ifsl.sys) allows a local user to gain higher system privileges by exploiting how the software handles data in memory. This is dangerous because it lets attackers bypass security restrictions and gain administrator-level access.
An elevation of privilege vulnerability exists in ws2ifsl.sys (Winsock driver) due to improper memory object handling. A local, authenticated attacker can exploit this to escalate privileges to SYSTEM level. The vulnerability requires local access but does not require user interaction.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.