Vulnerability record · CVE-2019-1388 · published 12 November 2019
CVE-2019-1388: Windows Certificate Dialog privilege escalation flaw
Microsoft · Windows 10 1507
The Windows Certificate Dialog does not properly enforce user privileges, allowing a local user to elevate to a higher integrity level. It matters because the flaw affects a broad set of Windows client and server releases and is listed in CISA's Known Exploited Vulnerabilities catalog.
Description
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Certificate Dialog Elevation of Privilege Vulnerability'.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 high severity, CISA KEV listing with ransomware use, and a wide affected Windows product set make this a high-priority local privilege escalation to remediate.
What it is
The Windows Certificate Dialog does not properly enforce user privileges, allowing a local user to elevate to a higher integrity level. It matters because the flaw affects a broad set of Windows client and server releases and is listed in CISA's Known Exploited Vulnerabilities catalog.
Impact
An attacker who can run code on a host gains elevated privileges, typically SYSTEM, enabling full control of the machine. That access can be used to disable defenses, move laterally, or deploy ransomware.
Attack surface
The vector is local (AV:L) with low privileges required (PR:L) and no user interaction (UI:N), so the attacker must already have a foothold or interactive session on the target. It is not remotely reachable and needs no victim action beyond the attacker's own local execution.
Exploitation
CVE-2019-1388 is in CISA KEV with a due date of 2023-04-28 and is flagged for known ransomware campaign use; EPSS 30-day probability is about 8.6 percent (94.8th percentile). No public exploit code or in-the-wild detail beyond KEV is provided in this record.
What to do
- Apply the Microsoft security update referenced in the vendor advisory MSRC CVE-2019-1388 as the first action.
- Restrict interactive logon and local execution rights to only users who need them, reducing the pool of accounts that can trigger the flaw.
- Enforce least privilege and remove unnecessary local administrator membership on endpoints and servers.
- Monitor and constrain use of the certificate dialog and related UI paths on high-value hosts where feasible.
- Track KEV remediation deadlines and verify patched status across all listed Windows client and server versions.
Detection
- Alert on unexpected process creation where a child process (for example cmd.exe or powershell.exe) is spawned from certificate or crypt UI host processes.
- Monitor for privilege escalation indicators such as new SYSTEM-level processes started by non-administrative user sessions.
- Audit Windows security logs for token or integrity-level changes and suspicious use of certificate dialog components.
- Correlate local logon events with subsequent high-integrity process creation on endpoints covered by the affected product list.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-1388 to the Known Exploited Vulnerabilities catalog on 7 April 2023 as "Microsoft Windows Certificate Dialog Privilege Escalation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 28 April 2023.
Affected products
14 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1388 | PatchVendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-19-975/ | Third Party Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1388 | PatchVendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-19-975/ | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-1388 | US Government Resource |
Track CVE-2019-1388 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-1388), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.