CVE-2019-1322 is an elevation of privilege vulnerability in Microsoft Windows, affecting versions including Windows 10 (1803, 1809, 1903) and Windows Server (1803, 1903, 2019). This vulnerability, with a CVSS score of 7.8 (HIGH), allows a local attacker with low privileges to achieve high impact on confidentiality, integrity, and availability. It is actively exploited, listed in CISA's KEV catalog, and has known Metasploit modules and ExploitDB entries available. Community discussion and media coverage indicate significant attention, with reports of Russian-speaking hackers exploiting it in attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:arm64:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:x64:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:x86:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:arm64:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.