vulnerability
Microsoft Windows: CVE-2019-0623: Win32k Elevation of Privilege Vulnerability
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:L/AC:L/Au:N/C:C/I:C/A:C) | Feb 12, 2019 | Feb 12, 2019 | Sep 5, 2025 |
Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
Feb 12, 2019
Added
Feb 12, 2019
Modified
Sep 5, 2025
Description
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.
Solutions
microsoft-windows-windows_10-1507-kb4487018microsoft-windows-windows_10-1607-kb4487026microsoft-windows-windows_10-1703-kb4487020microsoft-windows-windows_10-1709-kb4486996microsoft-windows-windows_10-1803-kb4487017microsoft-windows-windows_server_2012-kb4486993microsoft-windows-windows_server_2012_r2-kb4487028microsoft-windows-windows_server_2016-1607-kb4487026msft-kb4486564-11fbac8f-a728-4e04-8372-8cddd6574ab0msft-kb4486564-7fbfe52a-2daf-44e1-a302-23301cbf4a23msft-kb4486564-85229e47-cf6f-468c-929d-a35cd8c7429fmsft-kb4486564-f550e112-2700-4bf2-a35f-92e3fecabe4emsft-kb4486564-fb886c0e-d5c2-439e-afd9-d6ff4fc7c211msft-kb4486564-fd4d0cb3-e518-47b9-8f3c-6df6b338e56amsft-kb4486993-5a996d53-fc95-4966-9610-84d959807d5fmsft-kb4486993-a2e58465-7d64-45ec-bb9e-1c26d4e6ed4bmsft-kb4487019-315a75ce-db3f-4064-96bb-47870282c3e2msft-kb4487019-784c5fee-e524-4f80-a62d-4e2431fd0096msft-kb4487019-fda7b4e6-5280-4fd1-819c-c55e67f69009msft-kb4487028-475e8ece-4ef7-4eee-971e-572fd822b57bmsft-kb4487028-e5090f1a-2ee0-441f-9463-d61d9aba3d53
References
- BID-106891
- CVE-2019-0623
- https://attackerkb.com/topics/CVE-2019-0623
- https://support.microsoft.com/help/4486993
- https://support.microsoft.com/help/4486996
- https://support.microsoft.com/help/4487017
- https://support.microsoft.com/help/4487018
- https://support.microsoft.com/help/4487020
- https://support.microsoft.com/help/4487026
- https://support.microsoft.com/help/4487028
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.