Microsoft Win32k Privilege Escalation Vulnerability
cve CVE-2019-1458 3 sources, 3 claims · Watch
CISA Known Exploited Vulnerabilities writes:
Microsoft Win32k Privilege Escalation Vulnerability A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP. Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-1458 the claim
Microsoft Win32k Privilege Escalation Vulnerability A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP. Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-1458 the claim
What each source says
| Property | Source | Said | Means here |
|---|---|---|---|
| Author author | Exploit-DB | piotrflorczykreceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "piotrflorczyk",
"codes": "CVE-2019-1458",
"date_added": "2020-03-09",
"date_published": "2020-03-03",
"date_updated": "2020-03-09",
"description": "Microsoft Windows - 'WizardOpium' Local Privilege Escalation",
"file": "exploits/windows/local/48180.cpp",
"id": "48180",
"platform": "windows",
"port": "",
"screenshot_url": "",
"source_url": "https://github.com/piotrflorczyk/cve-2019-1458_POC/blob/243ed92a0141bdcdcfeef554fc2a35534fc2c68c/cve-2019-1458.cpp",
"tags": "",
"type": "local",
"verified": "0"
} | — |
| Due date due_date | CISA Known Exploited Vulnerabilities | 2022-07-10receipt
What the source handed over{
"cveID": "CVE-2019-1458",
"cwes": "",
"dateAdded": "2022-01-10",
"dueDate": "2022-07-10",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Known",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2019-1458",
"product": "Win32k",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.",
"vendorProject": "Microsoft",
"vulnerabilityName": "Microsoft Win32k Privilege Escalation Vulnerability"
} | — |
| Exploited exploited | CISA Known Exploited Vulnerabilities | yesreceipt
What the source handed over{
"cveID": "CVE-2019-1458",
"cwes": "",
"dateAdded": "2022-01-10",
"dueDate": "2022-07-10",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Known",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2019-1458",
"product": "Win32k",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.",
"vendorProject": "Microsoft",
"vulnerabilityName": "Microsoft Win32k Privilege Escalation Vulnerability"
} | — |
| Forensic triage forensic_triage | CISA Known Exploited Vulnerabilities | falsereceipt
What the source handed over{
"cveID": "CVE-2019-1458",
"cwes": "",
"dateAdded": "2022-01-10",
"dueDate": "2022-07-10",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Known",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2019-1458",
"product": "Win32k",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.",
"vendorProject": "Microsoft",
"vulnerabilityName": "Microsoft Win32k Privilege Escalation Vulnerability"
} | — |
| Known ransomware campaign use known_ransomware_campaign_use | CISA Known Exploited Vulnerabilities | Knownreceipt
What the source handed over{
"cveID": "CVE-2019-1458",
"cwes": "",
"dateAdded": "2022-01-10",
"dueDate": "2022-07-10",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Known",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2019-1458",
"product": "Win32k",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.",
"vendorProject": "Microsoft",
"vulnerabilityName": "Microsoft Win32k Privilege Escalation Vulnerability"
} | — |
| Platform platform not compared | Exploit-DB | windowsreceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "piotrflorczyk",
"codes": "CVE-2019-1458",
"date_added": "2020-03-09",
"date_published": "2020-03-03",
"date_updated": "2020-03-09",
"description": "Microsoft Windows - 'WizardOpium' Local Privilege Escalation",
"file": "exploits/windows/local/48180.cpp",
"id": "48180",
"platform": "windows",
"port": "",
"screenshot_url": "",
"source_url": "https://github.com/piotrflorczyk/cve-2019-1458_POC/blob/243ed92a0141bdcdcfeef554fc2a35534fc2c68c/cve-2019-1458.cpp",
"tags": "",
"type": "local",
"verified": "0"
} | — |
| Platform platform not compared | Metasploit exploit modules | Windowsreceipt
What the source handed over{
"actions": [],
"aliases": [],
"arch": "x64",
"author": [
"piotrflorczyk",
"unamer",
"timwr"
],
"autofilter_ports": [],
"autofilter_services": [],
"check": true,
"default_credential": false,
"description": "This module exploits CVE-2019-1458, an arbitrary pointer dereference vulnerability\n within win32k which occurs due to an uninitalized variable, which allows user mode attackers\n to write a limited amount of controlled data to an attacker controlled address\n in kernel memory. By utilizing this vulnerability to execute controlled writes\n to kernel memory, an attacker can gain arbitrary code execution\n as the SYSTEM user.\n\n This module has been tested against Windows 7 x64 SP1. Offsets within the\n exploit code may need to be adjusted to work with other versions of Windows.\n The exploit can only be triggered once against the target and can cause the\n target machine to reboot when the session is terminated.",
"disclosure_date": "2019-12-10",
"fullname": "exploit/windows/local/cve_2019_1458_wizardopium",
"is_install_path": true,
"mod_time": "2026-04-22 11:58:46 +0000",
"name": "Microsoft Windows Uninitialized Variable Local Privilege Elevation",
"needs_cleanup": null,
"notes": {
"Reliability": [
"unreliable-session"
],
"SideEffects": [
"ioc-in-logs"
],
"Stability": [
"crash-os-restarts"
]
},
"path": "/modules/exploits/windows/local/cve_2019_1458_wizardopium.rb",
"platform": "Windows",
"post_auth": false,
"rank": 300,
"ref_name": "windows/local/cve_2019_1458_wizardopium",
"references": [
"CVE-2019-1458",
"URL-https://github.com/unamer/CVE-2019-1458",
"URL-https://github.com/piotrflorczyk/cve-2019-1458_POC",
"URL-https://securelist.com/windows-0-day-exploit-cve-2019-1458-used-in-operation-wizardopium/95432/",
"URL-https://googleprojectzero.blogspot.com/p/rca-cve-2019-1458.html"
],
"rport": null,
"session_types": [
"meterpreter"
],
"targets": [
"Windows 7 x64"
],
"type": "exploit"
} | — |
| Product product | CISA Known Exploited Vulnerabilities | Win32kreceipt
What the source handed over{
"cveID": "CVE-2019-1458",
"cwes": "",
"dateAdded": "2022-01-10",
"dueDate": "2022-07-10",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Known",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2019-1458",
"product": "Win32k",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.",
"vendorProject": "Microsoft",
"vulnerabilityName": "Microsoft Win32k Privilege Escalation Vulnerability"
} | — |
| Rank rank | Metasploit exploit modules | 300 Normal. Reliable against a version range the module detects. receipt
What the source handed over{
"actions": [],
"aliases": [],
"arch": "x64",
"author": [
"piotrflorczyk",
"unamer",
"timwr"
],
"autofilter_ports": [],
"autofilter_services": [],
"check": true,
"default_credential": false,
"description": "This module exploits CVE-2019-1458, an arbitrary pointer dereference vulnerability\n within win32k which occurs due to an uninitalized variable, which allows user mode attackers\n to write a limited amount of controlled data to an attacker controlled address\n in kernel memory. By utilizing this vulnerability to execute controlled writes\n to kernel memory, an attacker can gain arbitrary code execution\n as the SYSTEM user.\n\n This module has been tested against Windows 7 x64 SP1. Offsets within the\n exploit code may need to be adjusted to work with other versions of Windows.\n The exploit can only be triggered once against the target and can cause the\n target machine to reboot when the session is terminated.",
"disclosure_date": "2019-12-10",
"fullname": "exploit/windows/local/cve_2019_1458_wizardopium",
"is_install_path": true,
"mod_time": "2026-04-22 11:58:46 +0000",
"name": "Microsoft Windows Uninitialized Variable Local Privilege Elevation",
"needs_cleanup": null,
"notes": {
"Reliability": [
"unreliable-session"
],
"SideEffects": [
"ioc-in-logs"
],
"Stability": [
"crash-os-restarts"
]
},
"path": "/modules/exploits/windows/local/cve_2019_1458_wizardopium.rb",
"platform": "Windows",
"post_auth": false,
"rank": 300,
"ref_name": "windows/local/cve_2019_1458_wizardopium",
"references": [
"CVE-2019-1458",
"URL-https://github.com/unamer/CVE-2019-1458",
"URL-https://github.com/piotrflorczyk/cve-2019-1458_POC",
"URL-https://securelist.com/windows-0-day-exploit-cve-2019-1458-used-in-operation-wizardopium/95432/",
"URL-https://googleprojectzero.blogspot.com/p/rca-cve-2019-1458.html"
],
"rport": null,
"session_types": [
"meterpreter"
],
"targets": [
"Windows 7 x64"
],
"type": "exploit"
} | — |
| Type type | Exploit-DB | localreceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "piotrflorczyk",
"codes": "CVE-2019-1458",
"date_added": "2020-03-09",
"date_published": "2020-03-03",
"date_updated": "2020-03-09",
"description": "Microsoft Windows - 'WizardOpium' Local Privilege Escalation",
"file": "exploits/windows/local/48180.cpp",
"id": "48180",
"platform": "windows",
"port": "",
"screenshot_url": "",
"source_url": "https://github.com/piotrflorczyk/cve-2019-1458_POC/blob/243ed92a0141bdcdcfeef554fc2a35534fc2c68c/cve-2019-1458.cpp",
"tags": "",
"type": "local",
"verified": "0"
} | — |
| Vendor project vendor_project | CISA Known Exploited Vulnerabilities | Microsoftreceipt
What the source handed over{
"cveID": "CVE-2019-1458",
"cwes": "",
"dateAdded": "2022-01-10",
"dueDate": "2022-07-10",
"forensicTriage": "No",
"knownRansomwareCampaignUse": "Known",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2019-1458",
"product": "Win32k",
"requiredAction": "Apply updates per vendor instructions.",
"shortDescription": "A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.",
"vendorProject": "Microsoft",
"vulnerabilityName": "Microsoft Win32k Privilege Escalation Vulnerability"
} | — |
| Verified verified | Exploit-DB | falsereceipt
What the source handed over{
"aliases": "",
"application_url": "",
"author": "piotrflorczyk",
"codes": "CVE-2019-1458",
"date_added": "2020-03-09",
"date_published": "2020-03-03",
"date_updated": "2020-03-09",
"description": "Microsoft Windows - 'WizardOpium' Local Privilege Escalation",
"file": "exploits/windows/local/48180.cpp",
"id": "48180",
"platform": "windows",
"port": "",
"screenshot_url": "",
"source_url": "https://github.com/piotrflorczyk/cve-2019-1458_POC/blob/243ed92a0141bdcdcfeef554fc2a35534fc2c68c/cve-2019-1458.cpp",
"tags": "",
"type": "local",
"verified": "0"
} | — |
vulnerability
| Microsoft Win32k Privilege Escalation Vulnerability zetlyn/cve-kev · 2022-01-10 | due_date 2022-07-10 exploited yes forensic_triage false known_ransomware_campaign_use Known product Win32k vendor_project Microsoft |
exploit
| Microsoft Windows Uninitialized Variable Local Privilege Elevation zetlyn/cve-metasploit · 2019-12-10 | platform Windows rank 300 | source |
| Microsoft Windows - 'WizardOpium' Local Privilege Escalation zetlyn/cve-exploitdb · 2020-03-03 | author piotrflorczyk platform windows type local verified false | source |