Microsoft patched CVE-2019-0859, a win32k.sys elevation-of-privilege flaw that Kaspersky said was exploited in the wild to give attackers higher privileges on affected Windows systems. The bug was a use-after-free condition in the CreateWindowEx path tied to WM_NCCREATE handling and manipulation of a window Function ID, allowing a freed window object to be reused for privilege escalation. Microsoft tracked the issue as a Win32k Elevation of Privilege Vulnerability in its Security Update Guide.
Kaspersky reported attacks against 64-bit Windows systems ranging from Windows 7 to older Windows 10 builds, with exploitation observed in March 2019. According to the report, the exploit used HMValidateHandle to help bypass ASLR, then launched PowerShell to fetch additional payload stages; the final payload unpacked shellcode and opened an HTTP reverse shell, giving the attacker full control of the compromised machine.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
Kaspersky Lab disclosed the win32k.sys vulnerability to Microsoft on March 17, 2019. Microsoft assigned the flaw CVE-2019-0859 and confirmed the vulnerability.
In March 2019, Kaspersky Lab detected an exploitation attempt against Microsoft Windows through its automatic Exploit Prevention systems. Further analysis led the company to identify a zero-day local privilege escalation vulnerability in win32k.sys that was being exploited in the wild.
After Kaspersky's disclosure, Microsoft released a security update to fix CVE-2019-0859, a Win32k elevation of privilege vulnerability. Microsoft also credited Kaspersky researchers Vasiliy Berdnikov and Boris Larin for the discovery.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.