EXPOSURES › CVE-2019-0863
CVE-2019-0863
HIGH ⌖ ON CISA KEV · EXPLOITEDA privilege escalation vulnerability in Windows Error Reporting allowed kernel-mode code execution, listed in CISA's KEV catalog as actively exploited.
The Windows Error Reporting (WER) component mishandled files, enabling attackers to escalate privileges and execute arbitrary code in kernel mode. DIB organizations must ensure all Windows systems are patched against CVE-2019-0863, as its inclusion in the KEV catalog confirms active exploitation in the wild. Failure to patch exposes systems to remote code execution and severe compliance violations under NIST 800-171.
Shame score — A known privilege escalation vulnerability was actively exploited in the wild and cataloged by CISA, indicating a failure to patch a critical flaw that could lead to full system compromise.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Error Reporting (WER) contains a privilege escalation vulnerability due to the way it handles files, allowing for code execution in kernel mode.
"Microsoft Windows Error Reporting (WER) contains a privilege escalation vulnerability due to the way it handles files, allowing for code execution in kernel mode."
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |