LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-1315: Microsoft Windows Error Reporting Manager Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 15, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Apr 5, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-1315 to its Known Exploited Vulnerabilities catalog on Mar 15, 2022, with a federal patch deadline of Apr 5, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted…

CVE-2019-1315 is a privilege escalation vulnerability in the Windows Error Reporting manager on Microsoft Windows. It stems from improper handling of hard links, which can let an attacker overwrite a targeted file and gain elevated privileges on the system. Privilege escalation flaws matter because they turn limited access—often obtained through phishing, malware, or another initial foothold—into full administrative control. CISA notes this issue has been used by ransomware operators, so unpatched systems remain attractive targets for attackers seeking to deepen their hold and deploy further payloads.

How it works

The underlying weakness is CWE-59: improper link resolution before file access, specifically involving hard links. Windows Error Reporting manager fails to handle hard links safely. An attacker who already has some level of access on the machine can abuse this behavior to cause the privileged Error Reporting component to operate on a file the attacker controls via a hard link. Successful exploitation allows the attacker to overwrite a chosen file in a way that results in elevated status.

Exact exploit mechanics, required starting privileges, and precise conditions are not detailed here; defenders should treat this as a local privilege-escalation path that depends on the Error Reporting service interacting with attacker-influenced links. Confirm full technical specifics against the vendor advisory.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows systems that include the Windows Error Reporting manager. This component is present on typical client and server installations of Windows. Inventory efforts should focus on identifying Windows hosts and confirming whether they have received the security update that addresses CVE-2019-1315.

How to remediate

Patch first. Apply the updates Microsoft released for this vulnerability according to the vendor advisory and CISA’s required action: apply updates per vendor instructions. Use your standard patch deployment process—WSUS, Microsoft Endpoint Configuration Manager, Intune, or equivalent—to push the fix and verify installation across the estate.

If you can't patch immediately

When immediate patching is not possible, reduce risk with compensating controls until the update can be applied.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities, including those known to be used with ransomware, frequently appear in breach chains after an initial foothold. If you suspect compromise, isolate affected hosts, preserve logs, and follow your incident-response process to determine whether credentials, files, or other data were accessed. You can also run a free exposure scan of your email addresses to check whether they appear in known breach datasets and take follow-up steps such as password resets and MFA enforcement where appropriate.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-59
Added to CISA KEVMar 15, 2022
Federal patch deadlineApr 5, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities