CVE-2019-0863

HIGH(7.8)KEV

Microsoft Windows Error Reporting (WER) Privilege Escalation Vulnerability

Description

CVE-2019-0863 is a high-severity privilege escalation vulnerability in the Microsoft Windows Error Reporting (WER) service. The flaw exists in the way WER handles files, allowing a local attacker with low-level privileges to execute code in kernel mode and gain elevated privileges on the system. CISA has added CVE-2019-0863 to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. With an EPSS score of 6.4% (90.9th percentile), this Windows privilege escalation vulnerability poses a significant risk, particularly when chained with other initial access exploits.

KEV Information

Vendor
Microsoft
Product
Windows
Date Added
November 3, 2021
Due Date
May 3, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9

Affected Products

VendorProductVersion
microsoftwindows 10 1507-
microsoftwindows 10 1607-
microsoftwindows 10 1703-
microsoftwindows 10 1709-
microsoftwindows 10 1803-
microsoftwindows 10 1809-
microsoftwindows 10 1903-
microsoftwindows 7-
microsoftwindows 8.1-
microsoftwindows rt 8.1-
microsoftwindows server 1803-
microsoftwindows server 1903-
microsoftwindows server 2008r2
microsoftwindows server 2012-; r2
microsoftwindows server 2016-
microsoftwindows server 2019-

Multiple CVSS Assessments

Source: [email protected](Primary)
7.8
HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
7.8
HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

Privilege Escalation via Windows Error Reporting

This vulnerability involves improper handling of files within the Windows Error Reporting service, enabling an attacker to escalate privileges from a low-privilege user to kernel-level code execution. The WER service runs with elevated permissions and its file handling routines do not adequately validate operations, creating an exploitable privilege boundary.

Learn more: CVE-2019-0863 — NVD Detail

Impact Analysis

CVE-2019-0863 carries a CVSS 3.1 score of 7.8 (HIGH), indicating a serious threat to affected Windows systems. The vulnerability is locally exploitable with low attack complexity, requiring only low-level privileges and no user interaction, which means any authenticated user on the system can potentially exploit it. Successful exploitation compromises confidentiality, integrity, and availability at the highest level, as the attacker gains kernel-mode code execution capabilities. This privilege escalation vulnerability is particularly dangerous when combined with a remote code execution vulnerability that provides initial access, allowing an attacker to progress from an unprivileged foothold to full system control. The EPSS score of 6.4% indicates an above-average probability of exploitation, placing it in the 90.9th percentile.

Exploit Maturity

CVE-2019-0863 has a confirmed exploit presence. Public exploit code is available via Packet Storm Security, documented as the "Angry Polar Bear 2" local privilege escalation exploit. CISA has confirmed active exploitation in the wild by including CVE-2019-0863 in the Known Exploited Vulnerabilities catalog. The EPSS score of 6.4% (90.9th percentile) indicates a significant probability of exploitation, placing this vulnerability well above the average exploitation threshold across all known CVEs.

Remediation

  1. Apply Microsoft security updates immediately as required by CISA KEV guidance. The patch was released as part of the May 2019 Patch Tuesday and addresses the file handling flaw in Windows Error Reporting.
  2. Verify that all affected Windows versions have been updated, including Windows 7, Windows 8.1, Windows 10 (versions 1507 through 1903), Windows RT 8.1, Windows Server 2008 R2, Windows Server 2012/R2, Windows Server 2016, Windows Server 2019, and Server versions 1803/1903.
  3. As an interim mitigation, restrict local user privileges and enforce the principle of least privilege across all endpoints. Limit the number of accounts with local interactive logon capabilities.
  4. Monitor WER-related process activity for anomalous behavior, particularly unusual file operations within the WER reporting directories. Deploy endpoint detection and response (EDR) solutions to detect privilege escalation attempts.
  5. Conduct a security review of affected systems to determine if the vulnerability was exploited prior to patching, looking for indicators such as unexpected kernel-mode process creation or unauthorized privilege changes.

Technical Details

CVE-2019-0863 resides in the Windows Error Reporting (WER) service's file handling routines. The WER service, which operates with elevated system privileges, improperly processes files during error reporting operations. A local attacker with low privileges can manipulate this file handling behavior to achieve code execution in kernel mode. The CVSS vector (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) confirms that the attack requires local access with low privileges, involves low complexity, and requires no user interaction. The scope remains unchanged, meaning the exploitation is confined to the vulnerable component's privilege domain, but since that domain is the Windows kernel, the effective impact is full system compromise with maximum impact on confidentiality, integrity, and availability.

Frequently Asked Questions

Is CVE-2019-0863 being actively exploited?

Yes. CVE-2019-0863 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Public exploit code known as "Angry Polar Bear 2" is available, and the EPSS score of 6.4% (90.9th percentile) further indicates a significant exploitation probability.

What products are affected by CVE-2019-0863?

CVE-2019-0863 affects a broad range of Microsoft Windows versions including Windows 7, Windows 8.1, Windows 10 (versions 1507, 1607, 1703, 1709, 1803, 1809, 1903), Windows RT 8.1, Windows Server 2008 R2, Windows Server 2012/R2, Windows Server 2016, Windows Server 2019, and Server versions 1803/1903.

How do I fix CVE-2019-0863?

Apply the Microsoft security update from the May 2019 Patch Tuesday immediately. Verify all affected Windows systems are updated. As an interim measure, enforce least privilege policies and monitor WER-related process activity for suspicious behavior.

How severe is CVE-2019-0863?

CVE-2019-0863 has a CVSS 3.1 score of 7.8 (HIGH). It enables local privilege escalation to kernel mode, which can lead to full system compromise. The EPSS score of 6.4% places it in the 90.9th percentile of exploitation probability.

CVSS Score

7.8
HIGH(7.8)

EPSS Score

EPSS Score5.21%
EPSS Percentile91.8%

Dates

PublishedMay 16, 2019
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.