CVE-2019-1215

HIGH(7.8)KEVRansomwareElevated Risk

Microsoft Windows Privilege Escalation Vulnerability

Description

CVE-2019-1215 is a high-severity privilege escalation vulnerability in Microsoft Windows. The flaw exists in how the ws2ifsl.sys (Winsock) driver handles objects in memory, allowing a locally authenticated attacker to execute code with elevated privileges. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. With an EPSS score of 7.7% (91.8th percentile) and known ransomware associations, CVE-2019-1215 represents a significant threat to unpatched Windows systems across a wide range of versions from Windows 7 through Windows Server 2019.

KEV Information

Vendor
Microsoft
Product
Windows
Date Added
November 3, 2021
Due Date
May 3, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
microsoftwindows 10 1507-
microsoftwindows 10 1607-
microsoftwindows 10 1703-
microsoftwindows 10 1709-
microsoftwindows 10 1803-
microsoftwindows 10 1809-
microsoftwindows 10 1903-
microsoftwindows 7-
microsoftwindows 8.1-
microsoftwindows rt 8.1-
microsoftwindows server 1803-
microsoftwindows server 1903-
microsoftwindows server 2008-; r2
microsoftwindows server 2012-; r2
microsoftwindows server 2016-
microsoftwindows server 2019-

Multiple CVSS Assessments

Source: [email protected](Primary)
7.8
HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
7.8
HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-269: Improper Privilege Management

Improper Privilege Management occurs when a software component does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control. In the case of CVE-2019-1215, the ws2ifsl.sys Winsock driver fails to properly manage memory objects, allowing an authenticated user to escalate privileges beyond their intended access level.

Learn more: CWE-269 — Improper Privilege Management

Impact Analysis

CVE-2019-1215 carries a CVSS 3.1 score of 7.8 (HIGH), reflecting significant risk to affected systems. The vulnerability requires local access to exploit, meaning an attacker must already have some level of access to the target system, though only low-level privileges are needed to trigger the flaw. No user interaction is required, making exploitation straightforward once an attacker gains initial access. Successful exploitation results in complete compromise of confidentiality, integrity, and availability, as the attacker can execute arbitrary code with elevated system-level privileges. The known association with ransomware campaigns makes this vulnerability particularly dangerous, as threat actors can leverage it to gain the elevated access needed to deploy encryption payloads and maximize damage across affected environments.

Exploit Maturity

CVE-2019-1215 is confirmed as actively exploited through its listing in the CISA Known Exploited Vulnerabilities catalog, with a remediation deadline of 2022-05-03. CISA has also flagged this vulnerability as having a known association with ransomware campaigns, significantly elevating its threat profile. The EPSS score of 7.7% (91.8th percentile) indicates a high probability of exploitation activity relative to other vulnerabilities. The KEV description notes this vulnerability is related to other Windows Elevation of Privilege vulnerabilities including CVE-2019-1253, CVE-2019-1278, and CVE-2019-1303, suggesting attackers may chain multiple privilege escalation flaws for maximum impact.

Remediation

  1. Apply Microsoft security updates immediately as mandated by the CISA KEV catalog directive. Install the September 2019 Patch Tuesday updates from the Microsoft Security Response Center.
  2. Verify that all affected Windows versions have been patched, including Windows 7, Windows 8.1, Windows 10 (all builds from 1507 through 1903), Windows RT 8.1, Windows Server 2008/R2, Windows Server 2012/R2, Windows Server 2016, Windows Server 2019, and Windows Server versions 1803 and 1903.
  3. Restrict local access to critical systems by implementing the principle of least privilege and auditing user account permissions to limit the attack surface for privilege escalation.
  4. Monitor for indicators of compromise including unexpected privilege escalation events, anomalous process creation with SYSTEM-level privileges, and suspicious activity involving the ws2ifsl.sys driver.
  5. Deploy endpoint detection and response (EDR) solutions to detect and block exploitation attempts targeting Winsock memory handling vulnerabilities, and review security event logs for evidence of prior exploitation.

Technical Details

CVE-2019-1215 is rooted in improper handling of memory objects by the ws2ifsl.sys driver, which is a core component of the Windows Winsock subsystem. The vulnerability arises when the driver fails to correctly manage object lifetimes in memory, creating a condition where an attacker with low-level local access can manipulate memory operations to escalate privileges. The CVSS vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H confirms that exploitation requires local access with low privileges and low complexity, with no user interaction needed. The scope remains unchanged, meaning the vulnerability affects only the vulnerable component, but the impact across all three CIA triad dimensions is rated high, reflecting full system compromise upon successful exploitation.

Frequently Asked Questions

Is CVE-2019-1215 being actively exploited?

Yes. CVE-2019-1215 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Additionally, this vulnerability has a known association with ransomware campaigns, making it a high-priority patching target.

What products are affected by CVE-2019-1215?

CVE-2019-1215 affects a broad range of Microsoft Windows versions including Windows 7, Windows 8.1, Windows RT 8.1, Windows 10 (versions 1507 through 1903), Windows Server 2008 and R2, Windows Server 2012 and R2, Windows Server 2016, Windows Server 2019, and Windows Server versions 1803 and 1903.

How do I fix CVE-2019-1215?

Apply the September 2019 security updates from Microsoft as directed in the CISA KEV catalog. Ensure all affected Windows systems are updated to the latest patched versions. If immediate patching is not possible, restrict local access and monitor for privilege escalation activity.

How severe is CVE-2019-1215?

CVE-2019-1215 has a CVSS 3.1 score of 7.8 (HIGH). With an EPSS score in the 91.8th percentile and known ransomware associations, this is a serious vulnerability that warrants immediate remediation for any organization running affected Windows systems.

CVSS Score

7.8
HIGH(7.8)

EPSS Score

EPSS Score19.25%
EPSS Percentile97.1%

Dates

PublishedSeptember 11, 2019
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.