CVE-2019-1215 — Microsoft Windows Privilege Escalation Vulnerability
CVE-2019-1215: Microsoft Windows Privilege Escalation Vulnerability
CISA Known Exploited Vulnerability (KEV)
| Vendor / project | Microsoft |
| Product | Windows |
| Date added | 2021-11-03 |
| Due date | 2022-05-03 |
| Ransomware campaign use | Known |
Description
Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in memory, allowing for privilege escalation. Successful exploitation allows an attacker to execute code with elevated privileges.
Required action (CISA)
Apply updates per vendor instructions.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2019-1215
References
- NVD: https://nvd.nist.gov/vuln/detail/CVE-2019-1215
- KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog