CVE-2019-0863
Microsoft Windows Error Reporting (WER) Privilege Escalation Vulnerability
Description
CVE-2019-0863 is a high-severity privilege escalation vulnerability in the Microsoft Windows Error Reporting (WER) service. The flaw exists in the way WER handles files, allowing a local attacker with low-level privileges to execute code in kernel mode and gain elevated privileges on the system. CISA has added CVE-2019-0863 to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. With an EPSS score of 6.4% (90.9th percentile), this Windows privilege escalation vulnerability poses a significant risk, particularly when chained with other initial access exploits.
KEV Information
CVSS Score
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| microsoft | windows 10 1507 | - |
| microsoft | windows 10 1607 | - |
| microsoft | windows 10 1703 | - |
| microsoft | windows 10 1709 | - |
| microsoft | windows 10 1803 | - |
| microsoft | windows 10 1809 | - |
| microsoft | windows 10 1903 | - |
| microsoft | windows 7 | - |
| microsoft | windows 8.1 | - |
| microsoft | windows rt 8.1 | - |
| microsoft | windows server 1803 | - |
| microsoft | windows server 1903 | - |
| microsoft | windows server 2008 | r2 |
| microsoft | windows server 2012 | -; r2 |
| microsoft | windows server 2016 | - |
| microsoft | windows server 2019 | - |
Multiple CVSS Assessments
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References
- http://packetstormsecurity.com/files/153008/Angry-Polar-Bear-2-Microsoft-Windows-Error-Reporting-Local-Privilege-Escalation.html(Third Party Advisory, VDB Entry)
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0863(Patch, Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0863(US Government Resource)
Weakness Type
Privilege Escalation via Windows Error Reporting
This vulnerability involves improper handling of files within the Windows Error Reporting service, enabling an attacker to escalate privileges from a low-privilege user to kernel-level code execution. The WER service runs with elevated permissions and its file handling routines do not adequately validate operations, creating an exploitable privilege boundary.
Learn more: CVE-2019-0863 — NVD Detail
Impact Analysis
CVE-2019-0863 carries a CVSS 3.1 score of 7.8 (HIGH), indicating a serious threat to affected Windows systems. The vulnerability is locally exploitable with low attack complexity, requiring only low-level privileges and no user interaction, which means any authenticated user on the system can potentially exploit it. Successful exploitation compromises confidentiality, integrity, and availability at the highest level, as the attacker gains kernel-mode code execution capabilities. This privilege escalation vulnerability is particularly dangerous when combined with a remote code execution vulnerability that provides initial access, allowing an attacker to progress from an unprivileged foothold to full system control. The EPSS score of 6.4% indicates an above-average probability of exploitation, placing it in the 90.9th percentile.
Exploit Maturity
CVE-2019-0863 has a confirmed exploit presence. Public exploit code is available via Packet Storm Security, documented as the "Angry Polar Bear 2" local privilege escalation exploit. CISA has confirmed active exploitation in the wild by including CVE-2019-0863 in the Known Exploited Vulnerabilities catalog. The EPSS score of 6.4% (90.9th percentile) indicates a significant probability of exploitation, placing this vulnerability well above the average exploitation threshold across all known CVEs.
Remediation
- Apply Microsoft security updates immediately as required by CISA KEV guidance. The patch was released as part of the May 2019 Patch Tuesday and addresses the file handling flaw in Windows Error Reporting.
- Verify that all affected Windows versions have been updated, including Windows 7, Windows 8.1, Windows 10 (versions 1507 through 1903), Windows RT 8.1, Windows Server 2008 R2, Windows Server 2012/R2, Windows Server 2016, Windows Server 2019, and Server versions 1803/1903.
- As an interim mitigation, restrict local user privileges and enforce the principle of least privilege across all endpoints. Limit the number of accounts with local interactive logon capabilities.
- Monitor WER-related process activity for anomalous behavior, particularly unusual file operations within the WER reporting directories. Deploy endpoint detection and response (EDR) solutions to detect privilege escalation attempts.
- Conduct a security review of affected systems to determine if the vulnerability was exploited prior to patching, looking for indicators such as unexpected kernel-mode process creation or unauthorized privilege changes.
Technical Details
CVE-2019-0863 resides in the Windows Error Reporting (WER) service's file handling routines. The WER service, which operates with elevated system privileges, improperly processes files during error reporting operations. A local attacker with low privileges can manipulate this file handling behavior to achieve code execution in kernel mode. The CVSS vector (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) confirms that the attack requires local access with low privileges, involves low complexity, and requires no user interaction. The scope remains unchanged, meaning the exploitation is confined to the vulnerable component's privilege domain, but since that domain is the Windows kernel, the effective impact is full system compromise with maximum impact on confidentiality, integrity, and availability.
Frequently Asked Questions
Is CVE-2019-0863 being actively exploited?
Yes. CVE-2019-0863 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Public exploit code known as "Angry Polar Bear 2" is available, and the EPSS score of 6.4% (90.9th percentile) further indicates a significant exploitation probability.
What products are affected by CVE-2019-0863?
CVE-2019-0863 affects a broad range of Microsoft Windows versions including Windows 7, Windows 8.1, Windows 10 (versions 1507, 1607, 1703, 1709, 1803, 1809, 1903), Windows RT 8.1, Windows Server 2008 R2, Windows Server 2012/R2, Windows Server 2016, Windows Server 2019, and Server versions 1803/1903.
How do I fix CVE-2019-0863?
Apply the Microsoft security update from the May 2019 Patch Tuesday immediately. Verify all affected Windows systems are updated. As an interim measure, enforce least privilege policies and monitor WER-related process activity for suspicious behavior.
How severe is CVE-2019-0863?
CVE-2019-0863 has a CVSS 3.1 score of 7.8 (HIGH). It enables local privilege escalation to kernel mode, which can lead to full system compromise. The EPSS score of 6.4% places it in the 90.9th percentile of exploitation probability.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.