First published: Tue Apr 09 2019(Updated: )
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0803, CVE-2019-0859.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 10 | =1607 | |
Microsoft Windows 10 | =1703 | |
Microsoft Windows 10 | =1709 | |
Microsoft Windows 10 | =1803 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2016 | =1709 | |
Microsoft Windows Server 2016 | =1803 | |
Microsoft Windows Server 2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0685 has a critical severity rating due to its potential for exploitation and allowing elevation of privilege.
To mitigate CVE-2019-0685, apply the latest security updates provided by Microsoft for the affected Windows versions.
CVE-2019-0685 affects multiple versions of Microsoft Windows 10 and Windows Server 2016 and 2019.
CVE-2019-0685 is classified as an elevation of privilege vulnerability in the Win32k component of Windows.
CVE-2019-0685 requires local access to the system for successful exploitation, making it less likely to be remotely exploited.