Microsoft Graphics Component
CVE-2019-1364 — Win32k Elevation of Privilege Vulnerability
Executive Summary
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. The update addresses this vulnerability by correcting how the Windows kernel-mode driver handles objects in memory.
Overview
7
CVSS HIGH
Important
MS Severity
Not Exploited
MS Exploit Status
N/A
MS Exploit Likelihood
CVSS Vector
ATTACK VECTOR
Local
ATTACK COMPLEXITY
High
PRIVILEGES REQUIRED
Low
USER INTERACTION
None
SCOPE
Unchanged
Temporal Score: 6.3
EPSS Score
0.02685
probability of exploitation in the next 30 days
0.83892 percentile - updated 2026-06-20
View on FIRST.org
Affected Products
10 affected products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 7 for 32-bit Systems Service Pack 1 | 4519976 (Monthly Rollup) 4520003 (Security Only) |
Important | Elevation of Privilege | Yes |
| Windows 7 for x64-based Systems Service Pack 1 | 4519976 (Monthly Rollup) 4520003 (Security Only) |
Important | Elevation of Privilege | Yes |
| Windows Server 2008 for 32-bit Systems Service Pack 2 | 4520002 (Monthly Rollup) 4520009 (Security Only) |
Important | Elevation of Privilege | Yes |
| Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) | 4520002 (Monthly Rollup) 4520009 (Security Only) |
Important | Elevation of Privilege | Yes |
| Windows Server 2008 for Itanium-Based Systems Service Pack 2 | 4520002 (Monthly Rollup) 4520009 (Security Only) |
Important | Elevation of Privilege | Yes |
| Windows Server 2008 for x64-based Systems Service Pack 2 | 4520002 (Monthly Rollup) 4520009 (Security Only) |
Important | Elevation of Privilege | Yes |
| Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) | 4520002 (Monthly Rollup) 4520009 (Security Only) |
Important | Elevation of Privilege | Yes |
| Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1 | 4519976 (Monthly Rollup) 4520003 (Security Only) |
Important | Elevation of Privilege | Yes |
| Windows Server 2008 R2 for x64-based Systems Service Pack 1 | 4519976 (Monthly Rollup) 4520003 (Security Only) |
Important | Elevation of Privilege | Yes |
| Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) | 4519976 (Monthly Rollup) 4520003 (Security Only) |
Important | Elevation of Privilege | Yes |
Patches
2 patches
| Article | Type | Restart |
|---|---|---|
4519976 (Monthly Rollup) 4520003 |
Monthly Rollup | Yes |
4520002 (Monthly Rollup) 4520009 |
Monthly Rollup | Yes |
Known Exploits
No known exploits have been linked for this CVE yet. When available, exploit references will be sourced from public repositories and may be unverified, incomplete, or non-functional. Always review code carefully before use in any environment.
Acknowledgments
References
On This Page