Microsoft Windows Shell CVE-2019-1053 Local Privilege Escalation Vulnerability
BID:108585
Info
Microsoft Windows Shell CVE-2019-1053 Local Privilege Escalation Vulnerability
| Bugtraq ID: | 108585 |
| Class: | Design Error |
| CVE: |
CVE-2019-1053 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 11 2019 12:00AM |
| Updated: | Jun 13 2019 06:00AM |
| Credit: | Microsoft |
| Vulnerable: |
Microsoft Windows Server 2019 0 Microsoft Windows Server 2016 0 Microsoft Windows Server 2012 R2 0 Microsoft Windows Server 2012 0 Microsoft Windows Server 2008 R2 for x64-based Systems SP1 Microsoft Windows Server 2008 R2 for Itanium-based Systems SP1 Microsoft Windows Server 2008 for x64-based Systems SP2 Microsoft Windows Server 2008 for Itanium-based Systems SP2 Microsoft Windows Server 2008 for 32-bit Systems SP2 Microsoft Windows Server 1903 0 Microsoft Windows Server 1803 0 Microsoft Windows RT 8.1 Microsoft Windows 8.1 for x64-based Systems 0 Microsoft Windows 8.1 for 32-bit Systems 0 Microsoft Windows 7 for x64-based Systems SP1 Microsoft Windows 7 for 32-bit Systems SP1 Microsoft Windows 10 Version 1903 for x64-based Systems 0 Microsoft Windows 10 Version 1903 for ARM64-based Systems 0 Microsoft Windows 10 Version 1903 for 32-bit Systems 0 Microsoft Windows 10 Version 1809 for x64-based Systems 0 Microsoft Windows 10 Version 1809 for ARM64-based Systems 0 Microsoft Windows 10 Version 1809 for 32-bit Systems 0 Microsoft Windows 10 Version 1803 for x64-based Systems 0 Microsoft Windows 10 Version 1803 for ARM64-based Systems 0 Microsoft Windows 10 Version 1803 for 32-bit Systems 0 Microsoft Windows 10 version 1709 for x64-based Systems 0 Microsoft Windows 10 Version 1709 for ARM64-based Systems 0 Microsoft Windows 10 version 1709 for 32-bit Systems 0 Microsoft Windows 10 version 1703 for x64-based Systems 0 Microsoft Windows 10 version 1703 for 32-bit Systems 0 Microsoft Windows 10 Version 1607 for x64-based Systems 0 Microsoft Windows 10 Version 1607 for 32-bit Systems 0 Microsoft Windows 10 for x64-based Systems 0 Microsoft Windows 10 for 32-bit Systems 0 Microsoft Internet Explorer 11 |
| Not Vulnerable: | |
Discussion
Microsoft Windows Shell CVE-2019-1053 Local Privilege Escalation Vulnerability
Microsoft Windows is prone to a local privilege-escalation vulnerability.
An attacker can exploit this issue to gain the elevated privileges on the system. Failed exploit attempts may result in a denial of service condition.
Microsoft Windows is prone to a local privilege-escalation vulnerability.
An attacker can exploit this issue to gain the elevated privileges on the system. Failed exploit attempts may result in a denial of service condition.
Exploit / POC
Microsoft Windows Shell CVE-2019-1053 Local Privilege Escalation Vulnerability
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
Microsoft Windows Shell CVE-2019-1053 Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Microsoft Windows Shell CVE-2019-1053 Local Privilege Escalation Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)
- Two more Microsoft zero-days uploaded on GitHub (zdnet.com)
- CVE-2019-1053 | Windows Shell Elevation of Privilege Vulnerability (Microsoft)