← Back to browse · API

CVE-2019-0808

Severity
HIGH
CVSS
7.8
EPSS
0.53298
Risk score
74.85
CISA KEV
Yes
PoC
No
Published
2021-11-03
Modified
2021-11-03
First seen
2026-08-07
Aliases
EUVD-2019-1563, GHSA-8WC3-99Q7-2QVC
Products
Microsoft:Win32k, Microsoft:Windows 7 for 32-bit Systems Service Pack 1, Microsoft:Windows 7 for x64-based Systems Service Pack 1, Microsoft:Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1, Microsoft:Windows Server 2008 R2 for x64-based Systems Service Pack 1, Microsoft:Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Core installation), Microsoft:Windows Server 2008 for 32-bit Systems Service Pack 2, Microsoft:Windows Server 2008 for 32-bit Systems Service Pack 2 (Core installation), Microsoft:Windows Server 2008 for Itanium-Based Systems Service Pack 2, Microsoft:Windows Server 2008 for x64-based Systems Service Pack 2, Microsoft:Windows Server 2008 for x64-based Systems Service Pack 2 (Core installation)
Sources
euvd EUVD-2019-1563
cisa.gov CVE-2019-0808

Description

Microsoft Win32k contains a privilege escalation vulnerability due to the component failing to properly handle objects in memory. Successful exploitation allows an attacker to run code in kernel mode.

References