CVE-2019-0808 is a critical elevation of privilege vulnerability in the Windows Win32k component, affecting Windows 7 and Server 2008. This flaw allows a local attacker to gain elevated privileges due to improper handling of objects in memory. With a CVSS score of 7.8 (High), it presents a significant risk, enabling full compromise of confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, with public exploit code available, including a Metasploit module. It has garnered substantial community attention and media coverage, indicating its widespread impact and the urgency of patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.