Record summary

CVE-2019-0735 has a selected CVSS score of 7.8 (high); EIP currently links 1 catalogued exploit.

Description

An elevation of privilege vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects in memory, aka 'Windows CSRSS Elevation of Privilege Vulnerability'.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List7 for 32-bit Systems Service Pack 1affected
7 for x64-based Systems Service Pack 1affected
8.1 for 32-bit systemsaffected
8.1 for x64-based systemsaffected
RT 8.1affected
10 for 32-bit Systemsaffected
10 for x64-based Systemsaffected
10 Version 1607 for 32-bit Systemsaffected
10 Version 1607 for x64-based Systemsaffected
10 Version 1703 for 32-bit Systemsaffected
10 Version 1703 for x64-based Systemsaffected
10 Version 1709 for 32-bit Systemsaffected
Showing 12 of 20 version ranges
CVE List2008 R2 for x64-based Systems Service Pack 1 (Core installation)affected
2008 R2 for Itanium-Based Systems Service Pack 1affected
2008 R2 for x64-based Systems Service Pack 1affected
2008 for 32-bit Systems Service Pack 2 (Core installation)affected
2012affected
2012 (Core installation)affected
2012 R2affected
2012 R2 (Core installation)affected
2016affected
2016 (Core installation)affected
version 1709 (Core Installation)affected
version 1803 (Core Installation)affected
Showing 12 of 18 version ranges

Proofs of concept

1

Catalogued exploits

ExploitDBMicrosoft Windows 10 1809 / 1709 - CSRSS SxSSrv Cached Manifest Privilege EscalationExploitDB exploitby Google Security ResearchNot analyzed1 file
ExploitDB

PoC details

References

4