Description
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1320, CVE-2019-1340.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- microsoft / Windows10 Version 1803 for ARM64-based Systems – 10 Version 1803 for ARM64-based Systems
- microsoft / Windows10 Version 1809 for ARM64-based Systems – 10 Version 1809 for ARM64-based Systems
- microsoft / Windows10 Version 1803 for 32-bit Systems – 10 Version 1803 for 32-bit Systems
- microsoft / Windows10 Version 1803 for x64-based Systems – 10 Version 1803 for x64-based Systems
- microsoft / Windows10 Version 1809 for 32-bit Systems – 10 Version 1809 for 32-bit Systems
- microsoft / Windows10 Version 1809 for x64-based Systems – 10 Version 1809 for x64-based Systems
- microsoft / Windows 10 Version 1903 for 32-bit Systemsunspecified – unspecified
- microsoft / Windows 10 Version 1903 for ARM64-based Systemsunspecified – unspecified
- microsoft / Windows 10 Version 1903 for x64-based Systemsunspecified – unspecified
- microsoft / Windows Serverversion 1803 (Core Installation) – version 1803 (Core Installation)
- microsoft / Windows Server2019 – 2019
- microsoft / Windows Server2019 (Core installation) – 2019 (Core installation)
- microsoft / Windows Server, version 1903 (Server Core installation)unspecified – unspecified
Exploits & proofs of concept
- exploit-dbMicrosoft UPnP - Local Privilege Elevation (Metasploit)by Metasploit
- exploit-dbMicrosoft Windows 10 Build 1803 < 1903 - 'COMahawk' Local Privilege Escalationby TomahawkAPT69
Updated 9m ago · 8 sources