Skip to main content

CVE detail

CVE-2019-0797

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0808.

CVSS 7.8 · HighBuzz score 52.5KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 52.5

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 19.5 · diversity 8.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
19.5
6 evidence mentions in the snapshot
Diversity score
8.0
3 sources across 1 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
6 source links · newest first
  • A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. Kindle Edition Paper Copy Once again thank you! Jackson County paid $400,000 to crooks after ransomare attack Venezuelan Minister declares Venezuelas Blackout may be caused by cyberattack carried by US Crooks use The Pirate Bay to spread […]

    newssecurityaffairs.comMar 17, 2019, 12:35 PM
  • One of the zero-day flaws (CVE-2019-0797) patched this week by Microsoft has been exploited in targeted attacks by several threats groups, including FruityArmor and SandCat APT groups. This week, Microsoft released Patch Tuesday security updates for March 2019 that address 64 flaws, including two Windows zero-day vulnerabilities exploited in targeted attacks. One of the flaws, […]

    newssecurityaffairs.comMar 13, 2019, 8:54 PM
  • One of the zero-day vulnerabilities patched this week by Microsoft has been exploited in targeted attacks by several threats groups, including the ones known as FruityArmor and SandCat, Kaspersky Lab revealed on Wednesday.

    newswww.securityweek.comMar 13, 2019, 10:05 AM
  • As part of the March 2019 Patch Tuesday, Microsoft has released fixes for 64 CVE-numbered vulnerabilities, 17 of which are rated Critical and 45 Important. Interestingly enough, none of the two vulnerabilities that are being actively exploited in the wild and of the four listed as being publicly known are rated Critical. Vulnerabilities exploited in the wild CVE-2019-0808 and CVE-2019-0797 are both Win32k Elevation of Privilege vulnerabilities under active attack. The first one was flagged … More →

    newswww.helpnetsecurity.comMar 13, 2019, 9:56 AM
  • Microsoft Patch Tuesday updates for March 2019 address 64 flaws, including two Windows zero-day vulnerabilities exploited in targeted attacks. Microsoft Patch Tuesday updates for March 2019 address 64 vulnerabilities, including two Windows zero-day flaws that have been exploited in targeted attacks. Four of the vulnerabilities addressed by Microsoft were publicly disclosed before fixes were released, […]

    newssecurityaffairs.comMar 13, 2019, 6:20 AM
  • Microsoft’s Patch Tuesday updates for March 2019 address over 60 vulnerabilities, including two Windows zero-day flaws that have been exploited in targeted attacks.

    newswww.securityweek.comMar 12, 2019, 7:20 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence