---
cve: "CVE-2019-0859"
severity: "HIGH"
cvss: 7.8
epss: "4.2%"
vendor: "Microsoft"
kev: true
exploited: true
published: "2019-04-09 21:29:02"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-23T06:27:03+02:00"
---

# CVE-2019-0859

> 7.8 HIGH · ⚠️ CISA KEV (1785 Tage) · 🔓 Exploited

## Beschreibung

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0685, CVE-2019-0803.

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0859>
- <https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0859>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2019-0859) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
