Skip to content
COOEY

EXPOSURES › CVE-2019-0880

CVE-2019-0880

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-05-23 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-0880 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedprivilege-escalation

A local privilege escalation flaw in Windows splwow64.exe allowed attackers to elevate from low to medium integrity, enabling further system compromise.

This vulnerability allowed local attackers to escalate privileges on Windows systems, bypassing security boundaries and enabling access to sensitive data or execution of malicious code. DIB organizations must ensure all Windows systems are patched against this known, actively exploited vulnerability to prevent lateral movement and data exfiltration. The failure stems from unpatched software handling, representing a classic negligence case where known CVEs remain unaddressed.

Shame score — A known, actively exploited vulnerability in a core OS component that attackers leveraged for privilege escalation, indicating severe negligence in patch management and system hardening.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system from low-integrity to medium-integrity.

AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized