Vulnerability record · CVE-2019-0880 · published 15 July 2019
CVE-2019-0880: Microsoft Windows splwow64.exe local privilege escalation
Microsoft · Windows 10 1507
splwow64.exe, the Windows print driver host process, mishandles certain calls, allowing a local user to elevate privileges. The flaw affects a broad set of Windows client and server releases, and Microsoft addressed it with a security update. Because it is a local elevation of privilege, it matters most as a post-compromise step to gain SYSTEM-level rights.
Description
A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls, aka 'Microsoft splwow64 Elevation of Privilege Vulnerability'.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is a high-severity local privilege escalation listed in CISA KEV, so it is actively exploited and should be patched promptly, though it requires prior local access.
What it is
splwow64.exe, the Windows print driver host process, mishandles certain calls, allowing a local user to elevate privileges. The flaw affects a broad set of Windows client and server releases, and Microsoft addressed it with a security update. Because it is a local elevation of privilege, it matters most as a post-compromise step to gain SYSTEM-level rights.
Impact
An attacker who already has code execution as a low-privileged user can escalate to higher privileges, potentially SYSTEM, on the affected host. That enables full control of the machine, including credential access and disabling of defenses.
Attack surface
The attack is local, requiring the attacker to run code on the target system; the CVSS vector shows low privileges required and no user interaction. It is not remotely reachable and no authentication beyond an existing local session is needed.
Exploitation
CVE-2019-0880 is listed in CISA's Known Exploited Vulnerabilities catalog, indicating exploitation in the wild, though no ransomware campaign use is recorded. EPSS gives a 30-day probability of about 2.3 percent (82nd percentile).
What to do
- Apply the Microsoft security update for CVE-2019-0880 to all affected Windows client and server versions.
- Prioritize patching on systems where untrusted users or processes can execute code locally.
- Restrict local logon and code execution rights to reduce the pool of accounts that can trigger the flaw.
- Monitor and limit use of splwow64.exe where printing is not required.
- Track remediation against the CISA KEV due date for this CVE.
Detection
- Alert on splwow64.exe spawning unexpected child processes or loading unusual modules.
- Monitor for privilege escalation from medium-integrity to SYSTEM-level tokens on endpoints.
- Review process creation events involving splwow64.exe outside normal print operations.
- Correlate local exploit activity with subsequent credential dumping or defense evasion behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-0880 to the Known Exploited Vulnerabilities catalog on 23 May 2022 as "Microsoft Windows Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 13 June 2022.
Affected products
13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0880 | PatchVendor Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0880 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0880 | US Government Resource |
Track CVE-2019-0880 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-0880), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.