CVE-2019-0859: Microsoft Win32k Privilege Escalation Vulnerability
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0803.
Other sources
Microsoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-0859?
CVE-2019-0859 has a high severity rating due to its potential for elevation of privilege attacks.
How do I fix CVE-2019-0859?
To fix CVE-2019-0859, apply the latest security updates provided by Microsoft for the affected versions of Windows.
Which versions of Windows are affected by CVE-2019-0859?
CVE-2019-0859 affects multiple versions of Windows, including Windows 10, 7, 8.1, and various Windows Server editions.
What are the potential impacts of exploiting CVE-2019-0859?
Exploiting CVE-2019-0859 could allow an attacker to gain elevated privileges on the system, potentially compromising sensitive data.
Is there a workaround for CVE-2019-0859?
Currently, the best approach to mitigate CVE-2019-0859 is to apply the security patches as provided by Microsoft.