CVE-2019-1322highunder attackransomware

CVE-2019-1322: high-severity vulnerability in Microsoft Windows

Published · Updated

91Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 7.8epss 19%
from disclosure to weapon34 days
Published on NVDOct 10
1st PoC+34d
metasploit+33d
CISA KEV+887d
exploitation probability
19%top 3% of all CVEs
observed exploitation
yesCISA + VulnCheck
4 public exploit(s)
Action required by CISAfederal deadline: 2022-04-05

Apply updates per vendor instructions.

In short

Windows has a flaw in how it processes authentication requests, allowing an attacker with local access to gain higher privileges than they should have. This is serious because it lets someone take control of the system.

Technical detail

An elevation of privilege vulnerability in Windows authentication handling allows a locally authenticated attacker to bypass privilege restrictions and gain SYSTEM-level access. The vulnerability stems from improper validation of authentication requests, affecting the privilege escalation boundary between user and system contexts.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1320, CVE-2019-1340.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.