CVE-2019-1215highunder attackransomwareCWE-269

CVE-2019-1215: high-severity vulnerability in Microsoft Windows

Published · Updated

81Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 7.8epss 19%
from disclosure to weapon117 days
Published on NVDSep 11
1st PoC+117d
CISA KEV+784d
exploitation probability
19%top 3% of all CVEs
observed exploitation
yesCISA + VulnCheck
4 public exploit(s)
Action required by CISAfederal deadline: 2022-05-03

Apply updates per vendor instructions.

In short

A flaw in Windows' network driver (ws2ifsl.sys) allows a local user to gain higher system privileges by exploiting how the software handles data in memory. This is dangerous because it lets attackers bypass security restrictions and gain administrator-level access.

Technical detail

An elevation of privilege vulnerability exists in ws2ifsl.sys (Winsock driver) due to improper memory object handling. A local, authenticated attacker can exploit this to escalate privileges to SYSTEM level. The vulnerability requires local access but does not require user interaction.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

An elevation of privilege vulnerability exists in the way that ws2ifsl.sys (Winsock) handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1253, CVE-2019-1278, CVE-2019-1303.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.