725
VMScore

CVE-2019-1132

Published: 15/07/2019 Updated: 24/08/2020
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows server 2008 -

microsoft windows server 2008 r2

microsoft windows 7 -

Exploits

#include <Windowsh> #include <iostream> /* EDB Note: Download ~ githubcom/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/47176zip */ /* PREPROCESSOR DEFINITIONS */ #define MN_SELECTITEM 0x1E5 #define MN_SELECTFIRSTVALIDITEM 0x1E7 #define MN_OPENHIERARCHY 0x01E3 #define MN_CANCELMENUS 0x1E6 #define MN_BUTTON ...

Github Repositories

EoP POC for CVE-2019-1132

CVE-2019-1132 EoP POC for CVE-2019-1132 This exploit is tested on Windows 7 x86 build 7601 (With June Patch installed)

Recent Articles

Microsoft Patch Tuesday – July 2019
Symantec Threat Intelligence Blog • Ratheesh PM • 10 Jul 2024

This month the vendor has patched 77 vulnerabilities, 16 of which are rated Critical.

Posted: 10 Jul, 201922 Min ReadThreat Intelligence SubscribeFollowtwitterfacebooklinkedinMicrosoft Patch Tuesday – July 2019This month the vendor has patched 77 vulnerabilities, 16 of which are rated Critical.As always, customers are advised to follow these security best practices: Install vendor patches as soon as they are available. Run all software with the least privileges required while still maintaining functionality. Avoid h...

New old Windows bug emerges, your 'strong' password is anything but, plus plenty more
The Register • Shaun Nichols in San Francisco • 15 Jul 2019

What you need to know from infosec land lately

Roundup Here is a brief look at some of the other security stories floating around right now. Earlier this month, an alert went out to Ruby on Rails developers after it was discovered that a popular package had been hijacked and injected with malicious code. Tute Costa was going through the gems used for his Ruby application and checking for updates when he noticed that something was amiss with the strong_password package. It was eventually concluded that the GitHub account managing the gem had ...

It's 2019 and SQL Server can be pwned by an SQL query, DHCP failover server failed by a packet, Edge, IE by webpages...
The Register • Shaun Nichols in San Francisco • 10 Jul 2019

Meanwhile, Adobe gives Flash the month off. SAP emits fixes, though Huawei website ████ ██████ security flaws ██████ customer info and biz operations at risk: ███████ patched

Patch Tuesday Summer is now firmly upon us, and depending on where you are, the weather could be just about anything from stupidly hot to unbearably wet and cold right now given the state of the climate. Well, anyway, Microsoft, Adobe, and SAP have dropped the July editions of their monthly security updates, so there's at least one storm to weather. How's that for a silky smooth transition? For Microsoft, July brings fixes for a total of 78 CVE-listed vulnerabilities. Among the more serious flaw...