CVE-2019-0797
Microsoft Win32k Privilege Escalation Vulnerability
Description
CVE-2019-0797 is a high-severity privilege escalation vulnerability in the Microsoft Win32k kernel-mode driver. The vulnerability occurs when the Win32k component fails to properly handle objects in memory, allowing a locally authenticated attacker to execute arbitrary code in kernel mode and gain elevated privileges on the system. A wide range of Windows operating systems are affected, including Windows 10 (multiple versions), Windows 8.1, and Windows Server 2012 through 2019. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. With an EPSS score of 6.09% (90.64th percentile), CVE-2019-0797 has a notable exploitation probability.
KEV Information
CVSS Score
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| microsoft | windows 10 1507 | - |
| microsoft | windows 10 1607 | - |
| microsoft | windows 10 1703 | - |
| microsoft | windows 10 1709 | - |
| microsoft | windows 10 1803 | - |
| microsoft | windows 10 1809 | - |
| microsoft | windows 8.1 | - |
| microsoft | windows rt 8.1 | - |
| microsoft | windows server 1709 | - |
| microsoft | windows server 1803 | - |
| microsoft | windows server 2012 | -; r2 |
| microsoft | windows server 2016 | - |
| microsoft | windows server 2019 | - |
Multiple CVSS Assessments
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0797(Patch, Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0797(US Government Resource)
Weakness Type
Win32k Memory Handling Vulnerability
This vulnerability results from improper handling of objects in memory by the Win32k kernel-mode driver. When the Win32k component fails to properly manage memory objects, an attacker with local access can manipulate these objects to execute arbitrary code with kernel-level privileges. This type of vulnerability in Windows kernel-mode drivers is a common target for privilege escalation attacks, as successful exploitation grants the attacker complete control over the affected system.
Learn more: CVE-2019-0797 — Microsoft Security Advisory
Impact Analysis
CVE-2019-0797 carries a CVSS 3.1 score of 7.8 (HIGH), indicating a significant privilege escalation threat. The attack vector is local, requiring the attacker to already have some level of access to the system, but the attack complexity is low and only low-level privileges are needed. No user interaction is required for exploitation. Confidentiality (High): An attacker who escalates to kernel mode gains access to all data on the system, including protected memory regions and credentials. Integrity (High): Kernel-level code execution allows the attacker to modify any system component, install rootkits, or tamper with security controls. Availability (High): Complete system disruption is possible, including the ability to cause system crashes or disable critical services. The scope is unchanged, meaning the impact stays within the Windows operating system context. This vulnerability is particularly dangerous when chained with a remote code execution vulnerability, allowing an attacker to first gain initial access and then escalate to full system control.
Exploit Maturity
CVE-2019-0797 is confirmed as actively exploited through its listing in the CISA Known Exploited Vulnerabilities catalog. The EPSS score of 6.09% (90.64th percentile) indicates a notable probability of exploitation, placing this vulnerability above the vast majority of CVEs in terms of exploitation likelihood. Win32k privilege escalation vulnerabilities are frequently targeted by advanced threat actors as part of multi-stage attack chains, where they are combined with initial access exploits to achieve full system compromise. Federal agencies were required to remediate by 2022-05-03 per CISA's binding operational directive.
Remediation
- Apply vendor patches immediately as mandated by CISA KEV: Apply updates per vendor instructions. Microsoft released security updates in March 2019 to address this vulnerability.
- Update all affected Windows systems, including: Windows 10 (versions 1507, 1607, 1703, 1709, 1803, 1809), Windows 8.1, Windows RT 8.1, Windows Server 1709, Windows Server 1803, Windows Server 2012 (including R2), Windows Server 2016, and Windows Server 2019.
- Implement the principle of least privilege across the environment to limit the impact of privilege escalation. Ensure users operate with standard user accounts rather than administrative accounts for daily tasks.
- Deploy endpoint detection and response (EDR) solutions capable of detecting kernel-level exploitation attempts, Win32k abuse patterns, and unusual privilege escalation activity. Monitor for suspicious system call patterns and token manipulation.
- Enable Credential Guard and other virtualization-based security features where supported to add additional layers of protection against kernel exploitation and credential theft.
Technical Details
CVE-2019-0797 is a privilege escalation vulnerability in the Windows Win32k kernel-mode driver caused by improper handling of objects in memory. The Win32k driver is a critical Windows kernel component responsible for the graphical subsystem, window management, and user interaction. When the driver fails to properly manage memory objects during certain operations, an attacker who has already obtained low-level access to the system can craft a specially-designed application that manipulates these memory objects to achieve arbitrary code execution in kernel mode. The CVSS vector (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) reflects that exploitation requires local access with low privileges, but once achieved, the impact across confidentiality, integrity, and availability is high. This CVE is distinct from the related CVE-2019-0808 Win32k vulnerability, though both target the same kernel component.
Frequently Asked Questions
Is CVE-2019-0797 being actively exploited?
Yes. CVE-2019-0797 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. The EPSS score of 6.09% (90.64th percentile) indicates a notable exploitation probability, and Win32k vulnerabilities are frequently targeted in advanced attack campaigns.
What products are affected by CVE-2019-0797?
CVE-2019-0797 affects multiple Windows operating systems including Windows 10 (versions 1507, 1607, 1703, 1709, 1803, 1809), Windows 8.1, Windows RT 8.1, Windows Server 1709, Server 1803, Server 2012 (including R2), Server 2016, and Server 2019.
How do I fix CVE-2019-0797?
Apply the security updates released by Microsoft in March 2019 for all affected Windows systems. Additionally, implement the principle of least privilege and deploy endpoint detection solutions capable of identifying kernel exploitation attempts.
How severe is CVE-2019-0797?
CVE-2019-0797 has a CVSS 3.1 score of 7.8 (HIGH) with high impact across confidentiality, integrity, and availability. As a kernel-level privilege escalation vulnerability with confirmed active exploitation, it poses a significant threat and should be remediated promptly.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.