Microsoft Win32k Privilege Escalation Vulnerability

cve CVE-2019-1458 3 sources, 3 claims · Watch

CISA Known Exploited Vulnerabilities writes:
Microsoft Win32k Privilege Escalation Vulnerability A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP. Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-1458 the claim

What each source says

PropertySourceSaidMeans here
Author
author
Exploit-DBpiotrflorczyk
receipt
Source
Exploit-DB
Its words
piotrflorczyk
Read by
field:author
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "piotrflorczyk",
  "codes": "CVE-2019-1458",
  "date_added": "2020-03-09",
  "date_published": "2020-03-03",
  "date_updated": "2020-03-09",
  "description": "Microsoft Windows - 'WizardOpium' Local Privilege Escalation",
  "file": "exploits/windows/local/48180.cpp",
  "id": "48180",
  "platform": "windows",
  "port": "",
  "screenshot_url": "",
  "source_url": "https://github.com/piotrflorczyk/cve-2019-1458_POC/blob/243ed92a0141bdcdcfeef554fc2a35534fc2c68c/cve-2019-1458.cpp",
  "tags": "",
  "type": "local",
  "verified": "0"
}
—
Due date
due_date
CISA Known Exploited Vulnerabilities2022-07-10
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
2022-07-10
Read by
field:dueDate
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 19:00 UTC
What the source handed over
{
  "cveID": "CVE-2019-1458",
  "cwes": "",
  "dateAdded": "2022-01-10",
  "dueDate": "2022-07-10",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://nvd.nist.gov/vuln/detail/CVE-2019-1458",
  "product": "Win32k",
  "requiredAction": "Apply updates per vendor instructions.",
  "shortDescription": "A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.",
  "vendorProject": "Microsoft",
  "vulnerabilityName": "Microsoft Win32k Privilege Escalation Vulnerability"
}
—
Exploited
exploited
CISA Known Exploited Vulnerabilitiesyes
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
yes
Read by
const:yes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 19:00 UTC
What the source handed over
{
  "cveID": "CVE-2019-1458",
  "cwes": "",
  "dateAdded": "2022-01-10",
  "dueDate": "2022-07-10",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://nvd.nist.gov/vuln/detail/CVE-2019-1458",
  "product": "Win32k",
  "requiredAction": "Apply updates per vendor instructions.",
  "shortDescription": "A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.",
  "vendorProject": "Microsoft",
  "vulnerabilityName": "Microsoft Win32k Privilege Escalation Vulnerability"
}
—
Forensic triage
forensic_triage
CISA Known Exploited Vulnerabilitiesfalse
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
No
Read by
field:forensicTriage
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 19:00 UTC
What the source handed over
{
  "cveID": "CVE-2019-1458",
  "cwes": "",
  "dateAdded": "2022-01-10",
  "dueDate": "2022-07-10",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://nvd.nist.gov/vuln/detail/CVE-2019-1458",
  "product": "Win32k",
  "requiredAction": "Apply updates per vendor instructions.",
  "shortDescription": "A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.",
  "vendorProject": "Microsoft",
  "vulnerabilityName": "Microsoft Win32k Privilege Escalation Vulnerability"
}
—
Known ransomware campaign use
known_ransomware_campaign_use
CISA Known Exploited VulnerabilitiesKnown
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Known
Read by
field:knownRansomwareCampaignUse
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 19:00 UTC
What the source handed over
{
  "cveID": "CVE-2019-1458",
  "cwes": "",
  "dateAdded": "2022-01-10",
  "dueDate": "2022-07-10",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://nvd.nist.gov/vuln/detail/CVE-2019-1458",
  "product": "Win32k",
  "requiredAction": "Apply updates per vendor instructions.",
  "shortDescription": "A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.",
  "vendorProject": "Microsoft",
  "vulnerabilityName": "Microsoft Win32k Privilege Escalation Vulnerability"
}
—
Platform
platform
not compared
Exploit-DBwindows
receipt
Source
Exploit-DB
Its words
windows
Read by
field:platform
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "piotrflorczyk",
  "codes": "CVE-2019-1458",
  "date_added": "2020-03-09",
  "date_published": "2020-03-03",
  "date_updated": "2020-03-09",
  "description": "Microsoft Windows - 'WizardOpium' Local Privilege Escalation",
  "file": "exploits/windows/local/48180.cpp",
  "id": "48180",
  "platform": "windows",
  "port": "",
  "screenshot_url": "",
  "source_url": "https://github.com/piotrflorczyk/cve-2019-1458_POC/blob/243ed92a0141bdcdcfeef554fc2a35534fc2c68c/cve-2019-1458.cpp",
  "tags": "",
  "type": "local",
  "verified": "0"
}
—
Platform
platform
not compared
Metasploit exploit modulesWindows
receipt
Source
Metasploit exploit modules
Its words
Windows
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 18:59 UTC
Original
open at the source
What the source handed over
{
  "actions": [],
  "aliases": [],
  "arch": "x64",
  "author": [
    "piotrflorczyk",
    "unamer",
    "timwr"
  ],
  "autofilter_ports": [],
  "autofilter_services": [],
  "check": true,
  "default_credential": false,
  "description": "This module exploits CVE-2019-1458, an arbitrary pointer dereference vulnerability\n          within win32k which occurs due to an uninitalized variable, which allows user mode attackers\n          to write a limited amount of controlled data to an attacker controlled address\n          in kernel memory. By utilizing this vulnerability to execute controlled writes\n          to kernel memory, an attacker can gain arbitrary code execution\n          as the SYSTEM user.\n\n          This module has been tested against Windows 7 x64 SP1. Offsets within the\n          exploit code may need to be adjusted to work with other versions of Windows.\n          The exploit can only be triggered once against the target and can cause the\n          target machine to reboot when the session is terminated.",
  "disclosure_date": "2019-12-10",
  "fullname": "exploit/windows/local/cve_2019_1458_wizardopium",
  "is_install_path": true,
  "mod_time": "2026-04-22 11:58:46 +0000",
  "name": "Microsoft Windows Uninitialized Variable Local Privilege Elevation",
  "needs_cleanup": null,
  "notes": {
    "Reliability": [
      "unreliable-session"
    ],
    "SideEffects": [
      "ioc-in-logs"
    ],
    "Stability": [
      "crash-os-restarts"
    ]
  },
  "path": "/modules/exploits/windows/local/cve_2019_1458_wizardopium.rb",
  "platform": "Windows",
  "post_auth": false,
  "rank": 300,
  "ref_name": "windows/local/cve_2019_1458_wizardopium",
  "references": [
    "CVE-2019-1458",
    "URL-https://github.com/unamer/CVE-2019-1458",
    "URL-https://github.com/piotrflorczyk/cve-2019-1458_POC",
    "URL-https://securelist.com/windows-0-day-exploit-cve-2019-1458-used-in-operation-wizardopium/95432/",
    "URL-https://googleprojectzero.blogspot.com/p/rca-cve-2019-1458.html"
  ],
  "rport": null,
  "session_types": [
    "meterpreter"
  ],
  "targets": [
    "Windows 7 x64"
  ],
  "type": "exploit"
}
—
Product
product
CISA Known Exploited VulnerabilitiesWin32k
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Win32k
Read by
field:product
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 19:00 UTC
What the source handed over
{
  "cveID": "CVE-2019-1458",
  "cwes": "",
  "dateAdded": "2022-01-10",
  "dueDate": "2022-07-10",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://nvd.nist.gov/vuln/detail/CVE-2019-1458",
  "product": "Win32k",
  "requiredAction": "Apply updates per vendor instructions.",
  "shortDescription": "A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.",
  "vendorProject": "Microsoft",
  "vulnerabilityName": "Microsoft Win32k Privilege Escalation Vulnerability"
}
—
Rank
rank
Metasploit exploit modules300
Normal. Reliable against a version range the module detects.
receipt
Source
Metasploit exploit modules
Its words
300
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 18:59 UTC
Original
open at the source
What the source handed over
{
  "actions": [],
  "aliases": [],
  "arch": "x64",
  "author": [
    "piotrflorczyk",
    "unamer",
    "timwr"
  ],
  "autofilter_ports": [],
  "autofilter_services": [],
  "check": true,
  "default_credential": false,
  "description": "This module exploits CVE-2019-1458, an arbitrary pointer dereference vulnerability\n          within win32k which occurs due to an uninitalized variable, which allows user mode attackers\n          to write a limited amount of controlled data to an attacker controlled address\n          in kernel memory. By utilizing this vulnerability to execute controlled writes\n          to kernel memory, an attacker can gain arbitrary code execution\n          as the SYSTEM user.\n\n          This module has been tested against Windows 7 x64 SP1. Offsets within the\n          exploit code may need to be adjusted to work with other versions of Windows.\n          The exploit can only be triggered once against the target and can cause the\n          target machine to reboot when the session is terminated.",
  "disclosure_date": "2019-12-10",
  "fullname": "exploit/windows/local/cve_2019_1458_wizardopium",
  "is_install_path": true,
  "mod_time": "2026-04-22 11:58:46 +0000",
  "name": "Microsoft Windows Uninitialized Variable Local Privilege Elevation",
  "needs_cleanup": null,
  "notes": {
    "Reliability": [
      "unreliable-session"
    ],
    "SideEffects": [
      "ioc-in-logs"
    ],
    "Stability": [
      "crash-os-restarts"
    ]
  },
  "path": "/modules/exploits/windows/local/cve_2019_1458_wizardopium.rb",
  "platform": "Windows",
  "post_auth": false,
  "rank": 300,
  "ref_name": "windows/local/cve_2019_1458_wizardopium",
  "references": [
    "CVE-2019-1458",
    "URL-https://github.com/unamer/CVE-2019-1458",
    "URL-https://github.com/piotrflorczyk/cve-2019-1458_POC",
    "URL-https://securelist.com/windows-0-day-exploit-cve-2019-1458-used-in-operation-wizardopium/95432/",
    "URL-https://googleprojectzero.blogspot.com/p/rca-cve-2019-1458.html"
  ],
  "rport": null,
  "session_types": [
    "meterpreter"
  ],
  "targets": [
    "Windows 7 x64"
  ],
  "type": "exploit"
}
—
Type
type
Exploit-DBlocal
receipt
Source
Exploit-DB
Its words
local
Read by
field:type
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "piotrflorczyk",
  "codes": "CVE-2019-1458",
  "date_added": "2020-03-09",
  "date_published": "2020-03-03",
  "date_updated": "2020-03-09",
  "description": "Microsoft Windows - 'WizardOpium' Local Privilege Escalation",
  "file": "exploits/windows/local/48180.cpp",
  "id": "48180",
  "platform": "windows",
  "port": "",
  "screenshot_url": "",
  "source_url": "https://github.com/piotrflorczyk/cve-2019-1458_POC/blob/243ed92a0141bdcdcfeef554fc2a35534fc2c68c/cve-2019-1458.cpp",
  "tags": "",
  "type": "local",
  "verified": "0"
}
—
Vendor project
vendor_project
CISA Known Exploited VulnerabilitiesMicrosoft
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Microsoft
Read by
field:vendorProject
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 19:00 UTC
What the source handed over
{
  "cveID": "CVE-2019-1458",
  "cwes": "",
  "dateAdded": "2022-01-10",
  "dueDate": "2022-07-10",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://nvd.nist.gov/vuln/detail/CVE-2019-1458",
  "product": "Win32k",
  "requiredAction": "Apply updates per vendor instructions.",
  "shortDescription": "A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.",
  "vendorProject": "Microsoft",
  "vulnerabilityName": "Microsoft Win32k Privilege Escalation Vulnerability"
}
—
Verified
verified
Exploit-DBfalse
receipt
Source
Exploit-DB
Its words
0
Read by
field:verified
Said since
2026-09-29 09:40 UTC
Last answered
2026-10-02 12:02 UTC
Original
open at the source
What the source handed over
{
  "aliases": "",
  "application_url": "",
  "author": "piotrflorczyk",
  "codes": "CVE-2019-1458",
  "date_added": "2020-03-09",
  "date_published": "2020-03-03",
  "date_updated": "2020-03-09",
  "description": "Microsoft Windows - 'WizardOpium' Local Privilege Escalation",
  "file": "exploits/windows/local/48180.cpp",
  "id": "48180",
  "platform": "windows",
  "port": "",
  "screenshot_url": "",
  "source_url": "https://github.com/piotrflorczyk/cve-2019-1458_POC/blob/243ed92a0141bdcdcfeef554fc2a35534fc2c68c/cve-2019-1458.cpp",
  "tags": "",
  "type": "local",
  "verified": "0"
}
—

vulnerability

Microsoft Win32k Privilege Escalation Vulnerability
zetlyn/cve-kev · 2022-01-10
due_date 2022-07-10 exploited yes forensic_triage false known_ransomware_campaign_use Known product Win32k vendor_project Microsoft

exploit

Microsoft Windows Uninitialized Variable Local Privilege Elevation
zetlyn/cve-metasploit · 2019-12-10
platform Windows rank 300 source
Microsoft Windows - 'WizardOpium' Local Privilege Escalation
zetlyn/cve-exploitdb · 2020-03-03
author piotrflorczyk platform windows type local verified false source