CVE-2019-0803
Microsoft Win32k Privilege Escalation Vulnerability
Description
CVE-2019-0803 is a high-severity privilege escalation vulnerability in the Microsoft Windows Win32k component. The Win32k component fails to properly handle objects in memory, allowing a locally authenticated attacker to execute arbitrary code in kernel mode. Successful exploitation grants full SYSTEM-level privileges, enabling an attacker to install programs, view, change, or delete data, or create new accounts with full user rights. CISA has added this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. With an EPSS score of 90.30% (99.6th percentile), the probability of exploitation is near certain.
KEV Information
CVSS Score
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| microsoft | windows 10 1507 | - |
| microsoft | windows 10 1607 | - |
| microsoft | windows 10 1703 | - |
| microsoft | windows 10 1709 | - |
| microsoft | windows 10 1803 | - |
| microsoft | windows 10 1809 | - |
| microsoft | windows 7 | - |
| microsoft | windows 8.1 | - |
| microsoft | windows rt 8.1 | - |
| microsoft | windows server 1709 | - |
| microsoft | windows server 1803 | - |
| microsoft | windows server 2008 | -; r2 |
| microsoft | windows server 2012 | -; r2 |
| microsoft | windows server 2016 | - |
| microsoft | windows server 2019 | - |
Multiple CVSS Assessments
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References
- http://packetstormsecurity.com/files/153034/Microsoft-Windows-Win32k-Privilege-Escalation.html(Third Party Advisory, VDB Entry)
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0803(Patch, Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0803(US Government Resource)
Weakness Type
No specific CWE has been assigned to CVE-2019-0803 by NVD. The vulnerability resides in the Win32k kernel component which fails to properly handle objects in memory. This type of memory corruption vulnerability in kernel-mode drivers typically involves improper object lifetime management, where freed or uninitialized memory is accessed during kernel operations, leading to privilege escalation. This CVE is distinct from CVE-2019-0685 and CVE-2019-0859, which address related but separate Win32k elevation of privilege issues.
Impact Analysis
CVE-2019-0803 carries a CVSS 3.1 score of 7.8 (HIGH), reflecting a serious local privilege escalation risk. The vulnerability requires local access with low privileges but has low attack complexity and requires no user interaction, making it straightforward to exploit once an attacker has an initial foothold on the target system. Successful exploitation fully compromises confidentiality, integrity, and availability, as the attacker gains kernel-mode code execution with SYSTEM privileges, enabling complete control over the affected system. The EPSS score of 90.30% (99.6th percentile) indicates near-certain exploitation activity. While this vulnerability is not currently associated with known ransomware campaigns, the ease of exploitation and the ability to achieve full SYSTEM access make it a high-priority target for attackers conducting post-compromise privilege escalation.
Exploit Maturity
CVE-2019-0803 is confirmed as actively exploited through its listing in the CISA Known Exploited Vulnerabilities catalog. Public exploit code is available via Packet Storm Security (Microsoft Windows Win32k Privilege Escalation), providing a publicly accessible proof-of-concept. The EPSS score of 90.30% (99.6th percentile) indicates near-certain exploitation activity, placing this vulnerability among the most actively exploited in the current threat landscape. CVE-2019-0803 is related to other Win32k elevation of privilege vulnerabilities (CVE-2019-0685 and CVE-2019-0859), and attackers frequently target Win32k vulnerabilities as a reliable class of privilege escalation vectors in Windows environments.
Remediation
- Apply vendor security updates immediately as directed by the CISA KEV catalog: Apply updates per vendor instructions. Install the April 2019 Patch Tuesday update from Microsoft that addresses the Win32k elevation of privilege vulnerability.
- Verify that all Windows endpoints have received the security update across the environment, as the Win32k component is present in all Windows versions and represents a common privilege escalation target.
- Implement endpoint detection and response (EDR) solutions capable of detecting kernel-mode exploitation attempts and suspicious privilege escalation patterns, particularly those targeting Win32k and other kernel-mode drivers.
- Apply the principle of least privilege across all user accounts and restrict local administrative access to minimize the available attack surface for post-compromise escalation.
- Monitor security logs for indicators of compromise associated with Win32k exploitation, including unusual system process behavior, unexpected privilege escalation events, and suspicious kernel driver activity. Conduct regular vulnerability assessments to identify unpatched systems.
Technical Details
CVE-2019-0803 is a privilege escalation vulnerability in the Windows Win32k kernel component caused by improper handling of objects in memory. The attack vector is local (CVSS vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), requiring a locally authenticated attacker with low privileges, but the exploit complexity is low and no user interaction is needed. The Win32k component is a critical kernel-mode driver responsible for the Windows graphical subsystem, and vulnerabilities in this component frequently enable privilege escalation from user mode to kernel mode. The memory corruption flaw allows an attacker to manipulate kernel objects to achieve arbitrary code execution in kernel mode, effectively bypassing all user-mode security boundaries. This vulnerability is distinct from CVE-2019-0685 and CVE-2019-0859, which address separate Win32k elevation of privilege vulnerabilities patched in the same timeframe, indicating a broader pattern of Win32k security issues in Windows kernel components.
Frequently Asked Questions
Is CVE-2019-0803 being actively exploited?
Yes. CVE-2019-0803 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. The EPSS score of 90.30% (99.6th percentile) indicates near-certain exploitation activity. While not currently associated with ransomware, the high exploitation probability warrants immediate attention.
What products are affected by CVE-2019-0803?
CVE-2019-0803 affects the Microsoft Win32k component present in Windows operating systems. Multiple Windows versions are affected where the Win32k kernel-mode driver improperly handles objects in memory. Organizations should consult the Microsoft Security Advisory for specific affected versions and the corresponding April 2019 security update.
How do I fix CVE-2019-0803?
Apply the April 2019 security update from Microsoft per vendor instructions. Ensure all Windows endpoints are patched across the environment. Additionally, deploy EDR solutions to detect exploitation attempts, enforce least-privilege policies, and monitor for suspicious privilege escalation events.
How severe is CVE-2019-0803?
CVE-2019-0803 has a CVSS 3.1 score of 7.8 (HIGH). While it requires local access, the low attack complexity, no user interaction requirement, and full impact on confidentiality, integrity, and availability make it a serious threat. The extremely high EPSS score (90.30%) confirms that this vulnerability is heavily targeted by attackers for privilege escalation.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.