CISA Known Exploited Vulnerability

CVE-2019-1215 Ransomware

Microsoft · Windows

Microsoft Windows Privilege Escalation Vulnerability

Date added
BOD 22-01 due date
CWE
Ransomware Known

CISA description

Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in memory, allowing for privilege escalation. Successful exploitation allows an attacker to execute code with elevated privileges.

Required action

Apply updates per vendor instructions.