LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-0863: Microsoft Windows Error Reporting (WER) Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-0863 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows Error Reporting (WER) contains a privilege escalation vulnerability due to the way it handles files, allowing for code execution in kernel mode.

CVE-2019-0863 is a privilege escalation vulnerability in Microsoft Windows Error Reporting (WER). It stems from the way WER handles files and can allow an attacker to achieve code execution in kernel mode. For IT and security teams this matters because successful local privilege escalation can turn a foothold on a single Windows host into full system control, enabling further lateral movement or persistence.

Public detail on exact mechanics is limited; defenders should treat any unpatched Windows system that uses WER as potentially in scope and confirm specifics against the vendor advisory.

How it works

The vulnerability exists in Microsoft Windows Error Reporting, a built-in component that collects and submits crash and diagnostic data. According to the available summary, the flaw arises from improper handling of files by WER. An attacker who already has the ability to run code at a lower privilege level on the system can abuse this handling to escalate privileges and execute code in kernel mode.

No CWE identifier is supplied in the given facts, and no exploit code or step-by-step abuse chain is provided. In general terms for this class of issue, the attacker supplies or manipulates files that WER processes, causing the component to perform privileged operations on the attacker’s behalf. Exact preconditions, file types, or trigger conditions must be confirmed against the Microsoft advisory.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows. WER is present by default on most modern Windows client and server installations, so inventory should cover workstations, servers, and any images or templates that include the Windows Error Reporting service or related binaries.

Telemetry signs of exploitation are not detailed in the provided facts. In general, look for unexpected process creations or file operations involving WER components running with elevated privileges, anomalous kernel-mode activity following user-mode crashes, or sudden privilege changes on accounts that should remain low-privileged. Correlate with EDR or Sysmon logs for process injection, unusual handle access to WER-related objects, and any post-exploitation indicators once a host is confirmed vulnerable.

How to remediate

The primary remediation is to apply the security update supplied by Microsoft for CVE-2019-0863. Follow the vendor’s instructions exactly; CISA’s required action is simply to apply updates per those instructions.

If you can't patch immediately

When immediate patching is not feasible, apply compensating controls to reduce the likelihood and impact of exploitation until the update can be installed.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities can be used as a stepping stone in larger intrusions that ultimately lead to data theft or ransomware. The facts supplied for CVE-2019-0863 do not document known ransomware use, yet any confirmed compromise should be treated as a potential breach. Conduct standard incident-response steps: isolate affected hosts, preserve forensic evidence, and determine whether sensitive data was accessed. As an additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether credentials or personal information have already appeared in public leaks.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities