EXPOSURES › CVE-2019-0880
CVE-2019-0880
HIGH ⌖ ON CISA KEV · EXPLOITEDA local privilege escalation flaw in Windows splwow64.exe allowed attackers to elevate from low to medium integrity, enabling further system compromise.
This vulnerability allowed local attackers to escalate privileges on Windows systems, bypassing security boundaries and enabling access to sensitive data or execution of malicious code. DIB organizations must ensure all Windows systems are patched against this known, actively exploited vulnerability to prevent lateral movement and data exfiltration. The failure stems from unpatched software handling, representing a classic negligence case where known CVEs remain unaddressed.
Shame score — A known, actively exploited vulnerability in a core OS component that attackers leveraged for privilege escalation, indicating severe negligence in patch management and system hardening.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system from low-integrity to medium-integrity.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |