CVE-2019-1322: high-severity vulnerability in Microsoft Windows
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply updates per vendor instructions.
Windows has a flaw in how it processes authentication requests, allowing an attacker with local access to gain higher privileges than they should have. This is serious because it lets someone take control of the system.
An elevation of privilege vulnerability in Windows authentication handling allows a locally authenticated attacker to bypass privilege restrictions and gain SYSTEM-level access. The vulnerability stems from improper validation of authentication requests, affecting the privilege escalation boundary between user and system contexts.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.