CVE-2019-1132 is an elevation of privilege vulnerability in the Win32k component of Windows 7 and Windows Server 2008, allowing an attacker to gain higher privileges on an affected system. This vulnerability has a CVSS score of 7.8 (HIGH), indicating a significant risk, as it can be exploited locally with low attack complexity and no user interaction, leading to high impact on confidentiality, integrity, and availability. It is actively exploited in the wild, with public exploit code available on ExploitDB, and has garnered substantial community discussion and media coverage, including its use by the Buhtrap Group in cyber-espionage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.