LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-1322: Microsoft Windows Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 15, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Apr 5, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-1322 to its Known Exploited Vulnerabilities catalog on Mar 15, 2022, with a federal patch deadline of Apr 5, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated…

CVE-2019-1322 is a privilege escalation vulnerability in Microsoft Windows that arises when the operating system improperly handles authentication requests. An attacker who successfully exploits it could run processes in an elevated context, gaining higher privileges than intended on the affected system.

This matters because privilege escalation is a common step after initial access: once an attacker has a foothold with limited rights, elevating to a more powerful context can enable broader compromise, persistence, and lateral movement. CISA notes known ransomware use of this vulnerability, so organizations running Windows should treat it as a priority for inventory and remediation. Confirm all product and update details against the Microsoft vendor advisory.

How it works

The flaw is a privilege escalation issue tied to how Windows processes authentication requests. In normal operation, the system should enforce strict boundaries so that a process or user session only obtains the privileges it is entitled to. When authentication handling is improper, an attacker already able to run code in a lower-privilege context may abuse that handling to obtain an elevated context.

At a high level, the attacker does not need to invent new credentials from nothing; they leverage the flawed authentication path so that Windows grants or applies elevated rights incorrectly. Exact exploit mechanics, preconditions, and any required local access are not detailed in the provided summary and must be confirmed against the vendor advisory. Defenders should assume that successful exploitation allows the attacker to run processes with higher privileges on the compromised host, which is especially dangerous on multi-user systems, servers, or endpoints that hold sensitive data or administrative tools.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows. Windows is typically present on endpoints, servers, domain controllers, and virtual machines across enterprise and smaller environments. Inventory every Windows host: physical workstations, laptops, member servers, and any cloud or on-premises images running Windows.

How to remediate

Patch first. Apply the updates Microsoft released for this vulnerability exactly as described in the vendor advisory and per CISA’s required action: apply updates per vendor instructions. Use your standard patch deployment pipeline (WSUS, Intune, SCCM, or equivalent), validate installation, and reboot if required by the update.

If you can't patch immediately

If immediate patching is blocked by change windows or compatibility testing, reduce risk with compensating controls until the vendor update is applied.

If your data may have been exposed

Actively exploited vulnerabilities, including those with known ransomware use, frequently lead to broader breaches once elevation succeeds. If you suspect exploitation, isolate affected hosts, preserve logs and memory for incident response, reset credentials that may have been exposed, and follow your incident response plan. As a further check on whether associated identities appear in known breach data, you can run a free exposure scan of your email addresses against published breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
Added to CISA KEVMar 15, 2022
Federal patch deadlineApr 5, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities