LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-0880: Microsoft Windows Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 23, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 13, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-0880 to its Known Exploited Vulnerabilities catalog on May 23, 2022, with a federal patch deadline of Jun 13, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system…

CVE-2019-0880 is a local elevation of privilege vulnerability in Microsoft Windows that involves how splwow64.exe handles certain calls. An attacker who already has a foothold at low integrity on an affected system could use a successful exploit to raise privileges to medium integrity. This matters because privilege escalation is a common step after initial access: it can let an adversary move from a constrained process or user context toward broader control of the host, install persistence, or reach data and tools that were previously out of reach.

Defenders should treat it as a post-compromise enabler rather than a remote entry point. Confirm exact product applicability, fixed builds, and deployment guidance only against the Microsoft advisory for this CVE.

How it works

The flaw is a local elevation of privilege issue centered on splwow64.exe, a Windows component involved in print-related and 32/64-bit interoperability paths. Public detail describes that the binary mishandles certain calls in a way that allows an attacker operating at low integrity to obtain medium integrity on the same system.

In practical terms, an adversary who can already run code in a low-integrity context (for example after landing via a separate vulnerability, malicious document, or limited user session) attempts to abuse the vulnerable handling path. Success yields higher integrity, which expands what the attacker can read, write, or execute under Windows integrity and privilege models. The CWE class is not specified in the provided record; treat it generically as a local privilege-escalation weakness in a system binary and verify any deeper root-cause notes in the vendor advisory. No remote unauthenticated exploitation path is described in the given facts.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows. splwow64.exe is a standard component on many Windows installations that support printing and WoW64 scenarios, so inventory should cover workstations and servers that run Windows and have the print subsystem or related features present.

If your environment uses third-party print or virtualization layers that interact with Windows printing, include those hosts in scope and validate with the vendor advisory.

How to remediate

Patch first. Apply the Microsoft updates that address CVE-2019-0880 exactly as directed in the vendor advisory and CISA’s required action (“Apply updates per vendor instructions”). Use your standard test-and-deploy pipeline, prioritize internet-facing or high-value systems that already allow local code execution by untrusted users, then roll out broadly.

If you can't patch immediately

Until the vendor update is deployed, shrink the attack surface and improve detection.

Track the exception with a clear deadline to patch; compensating controls degrade over time as attackers adapt.

If your data may have been exposed

Local elevation vulnerabilities are frequently chained after initial access and can contribute to broader compromise, data theft, or ransomware staging even when ransomware use is not specifically documented for this CVE. If you have indicators of exploitation or unexplained privilege changes on affected hosts, follow your incident-response process: isolate, preserve evidence, rotate credentials, and hunt for lateral movement. As a quick personal check, individuals can run a free exposure scan of their email addresses against known breach datasets to see whether their credentials already appear in public dumps, then force password changes and enable MFA where needed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
Added to CISA KEVMay 23, 2022
Federal patch deadlineJun 13, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities