IM
IronMonkey Threat Research

CVE-2019-0803 HIGH

Published: 2019-04-09 | Last Modified: 2026-06-17 | Status: Analyzed

Description

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0859.

Additional Descriptions (1)

Existe una vulnerabilidad de elevación de privilegios en Windows cuando el componente Win32k no puede manejar correctamente los objetos en la memoria, también conocido como 'Win32k Elevation of Privilege Vulnerability'. Este ID de CVE es diferente de CVE-2019-0685, CVE-2019-0859.

CVSS Metrics

Base Score: 7.8 (HIGH)

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 1.8

Impact Score: 5.9

Base Score: 7.2 (HIGH)

AV:L/AC:L/Au:N/C:C/I:C/A:C

Access VectorLOCAL
Access ComplexityLOW
AuthenticationNONE
Confidentiality ImpactCOMPLETE
Integrity ImpactCOMPLETE
Availability ImpactCOMPLETE

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 10.0

Weaknesses

Source Type Description
[email protected] Primary
en NVD-CWE-noinfo

Affected Products

Vendor Product Version Update Type
microsoft windows_10_1507 - <built-in method update of dict object at 0x7e60ba25d6c0> Operating System
microsoft windows_10_1507 - <built-in method update of dict object at 0x7e6110cf5c40> Operating System
microsoft windows_10_1607 - <built-in method update of dict object at 0x7e60ba25f080> Operating System
microsoft windows_10_1607 - <built-in method update of dict object at 0x7e611239ccc0> Operating System
microsoft windows_10_1703 - <built-in method update of dict object at 0x7e60ba25c7c0> Operating System
microsoft windows_10_1703 - <built-in method update of dict object at 0x7e60ba25f680> Operating System
microsoft windows_10_1709 - <built-in method update of dict object at 0x7e60ba25fcc0> Operating System
microsoft windows_10_1709 - <built-in method update of dict object at 0x7e60ba25d000> Operating System
microsoft windows_10_1709 - <built-in method update of dict object at 0x7e6110cf79c0> Operating System
microsoft windows_10_1803 - <built-in method update of dict object at 0x7e60ba25d040> Operating System
microsoft windows_10_1803 - <built-in method update of dict object at 0x7e613c4dedc0> Operating System
microsoft windows_10_1803 - <built-in method update of dict object at 0x7e6112395240> Operating System
microsoft windows_10_1809 - <built-in method update of dict object at 0x7e60ba25c500> Operating System
microsoft windows_10_1809 - <built-in method update of dict object at 0x7e6112373c40> Operating System
microsoft windows_10_1809 - <built-in method update of dict object at 0x7e60e8815880> Operating System
microsoft windows_7 - <built-in method update of dict object at 0x7e60e8814ec0> Operating System
microsoft windows_8.1 - <built-in method update of dict object at 0x7e6110cf5b40> Operating System
microsoft windows_rt_8.1 - <built-in method update of dict object at 0x7e60ba25c240> Operating System
microsoft windows_server_1709 - <built-in method update of dict object at 0x7e6110cf47c0> Operating System
microsoft windows_server_1803 - <built-in method update of dict object at 0x7e6110cf5500> Operating System
microsoft windows_server_2008 - <built-in method update of dict object at 0x7e611206e040> Operating System
microsoft windows_server_2008 r2 <built-in method update of dict object at 0x7e611239c200> Operating System
microsoft windows_server_2008 r2 <built-in method update of dict object at 0x7e60ba25f100> Operating System
microsoft windows_server_2012 - <built-in method update of dict object at 0x7e6110cf5f00> Operating System
microsoft windows_server_2012 r2 <built-in method update of dict object at 0x7e6110cf5580> Operating System
microsoft windows_server_2016 - <built-in method update of dict object at 0x7e60eb2b5b40> Operating System
microsoft windows_server_2019 - <built-in method update of dict object at 0x7e60ba25d400> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:x64:*
Yes cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:x86:*
Yes cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x64:*
Yes cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x86:*
Yes cpe:2.3:o:microsoft:windows_10_1703:-:*:*:*:*:*:x64:*
Yes cpe:2.3:o:microsoft:windows_10_1703:-:*:*:*:*:*:x86:*
Yes cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:arm64:*
Yes cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:x64:*
Yes cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:x86:*
Yes cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:arm64:*
Yes cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:x64:*
Yes cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:x86:*
Yes cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:arm64:*
Yes cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x64:*
Yes cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x86:*
Yes cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_server_1709:-:*:*:*:*:*:x64:*
Yes cpe:2.3:o:microsoft:windows_server_1803:-:*:*:*:*:*:x64:*
Yes cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*
Yes cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*
Yes cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
Yes cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*
Notification
Message here