CVE-2019-1458highunder attackransomware

CVE-2019-1458: high-severity vulnerability in Microsoft Windows

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 7.8epss 74%
from disclosure to weapon84 days
Published on NVDDec 10
1st PoC+84d
metasploitDec 10
CISA KEV+762d
exploitation probability
74%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
9 public exploit(s)
Action required by CISAfederal deadline: 2022-07-10

Apply updates per vendor instructions.

In short

Windows Win32k component has a flaw that allows an attacker with local access to run malicious code with higher system privileges, potentially taking full control of the computer.

Technical detail

The Win32k kernel-mode driver fails to properly validate and handle object references in memory, allowing local authenticated attackers to execute arbitrary code in kernel context via specially crafted Win32 API calls, resulting in privilege escalation to SYSTEM level.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.