Vulnerability record · CVE-2019-1322 · published 10 October 2019
CVE-2019-1322: Windows authentication handling privilege escalation
Microsoft · Windows 10 1803
Windows improperly handles authentication requests, allowing a local user to elevate privileges. The flaw affects several Windows 10 and Windows Server builds and is listed in CISA's Known Exploited Vulnerabilities catalog, so it matters for both patching and detection.
Description
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1320, CVE-2019-1340.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is a local privilege escalation with a public exploit and KEV listing including known ransomware use, though it requires an existing foothold on the host.
What it is
Windows improperly handles authentication requests, allowing a local user to elevate privileges. The flaw affects several Windows 10 and Windows Server builds and is listed in CISA's Known Exploited Vulnerabilities catalog, so it matters for both patching and detection.
Impact
An attacker who already has a foothold on the host can gain elevated privileges, potentially reaching administrative or SYSTEM-level access. That access can be used to disable defenses, move laterally, or deploy ransomware.
Attack surface
The CVSS vector is local (AV:L) with low privileges required (PR:L) and no user interaction (UI:N), so the attacker must already be able to run code on the target machine. It is not remotely reachable and does not require a victim to open a file or click a link.
Exploitation
CISA added this to KEV on 2022-03-15 with known ransomware campaign use, and a public exploit reference exists on Packet Storm. EPSS is 0.19205 (97th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Apply the Microsoft security update for CVE-2019-1322 to all affected Windows 10 and Windows Server builds.
- Prioritize patching hosts that are internet-facing or used for privileged administration, since KEV lists known ransomware use.
- Restrict local logon and code execution rights so unprivileged users cannot run arbitrary code on sensitive systems.
- Monitor for and remove unauthorized local accounts or tools that could be used to exploit local privilege escalation.
- Verify patch coverage across Windows 10 1803, 1809, 1903 and Windows Server 1803, 1903, 2019.
Detection
- Alert on unexpected creation of privileged local accounts or addition to Administrators/SYSTEM-equivalent groups.
- Monitor process creation for known local privilege escalation exploit tooling and unusual parent-child relationships involving authentication components.
- Review Windows security event logs for anomalous token or privilege use on hosts running unpatched builds.
- Correlate endpoint telemetry with KEV-listed exploitation attempts and ransomware precursor behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-1322 to the Known Exploited Vulnerabilities catalog on 15 March 2022 as "Microsoft Windows Privilege Escalation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 5 April 2022.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/155723/Microsoft-UPnP-Local-Privilege-Elevation.html | ExploitThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1322 | PatchVendor Advisory |
| http://packetstormsecurity.com/files/155723/Microsoft-UPnP-Local-Privilege-Elevation.html | ExploitThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1322 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-1322 | US Government Resource |
Track CVE-2019-1322 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-1322), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.