CVE-2019-1388
HIGH KEV RANSOMWAREWindows Certificate Dialog - Privilege Escalation
Title source: llmDescription
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Certificate Dialog Elevation of Privilege Vulnerability'.
Exploits (5)
References (3)
Scores
CVSS v3
7.8
EPSS
0.0921
EPSS Percentile
92.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2023-04-07
VulnCheck KEV
2022-03-24
InTheWild.io
2022-01-27
ENISA EUVD
EUVD-2019-9945
Ransomware Use
Confirmed
CWE
CWE-269
Status
published
Products (17)
microsoft/windows_10_1507
(2 CPE variants)
microsoft/windows_10_1607
(2 CPE variants)
microsoft/windows_10_1709
(3 CPE variants)
microsoft/windows_10_1803
(3 CPE variants)
microsoft/windows_10_1809
(3 CPE variants)
microsoft/windows_10_1903
(3 CPE variants)
microsoft/windows_7
microsoft/windows_8.1
microsoft/windows_rt_8.1
microsoft/windows_server_1903
... and 7 more
Published
Nov 12, 2019
KEV Added
Apr 07, 2023
Tracked Since
Feb 18, 2026