⚠ Actively exploited
Added to CISA KEV on 2021-11-03. Federal agencies required to patch by 2022-05-03. Required action: Apply updates per vendor instructions..

CVE-2019-1214Improper Restriction of Operations within the Bounds of a Memory Buffer in Microsoft Windows

Severity
7.8HIGHNVD
EPSS
3.7%
top 12.06%
CISA KEV
KEV
Added 2021-11-03
Due 2022-05-03
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedSep 11
KEV addedNov 3
KEV dueMay 3
Latest updateNov 15
CISA Required Action: Apply updates per vendor instructions.

Description

An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages22 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2q4x-j5p2-9wxv: An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Window2022-05-24
VulnCheck
Microsoft Windows Privilege Common Log File System (CLFS) Escalation Vulnerability2019

📋Vendor Advisories

3
Red Hat
bzip2: bzip2: Data integrity error when decompressing (with data integrity tests fail).2024-11-15
CISA
Microsoft Windows Privilege Common Log File System (CLFS) Escalation Vulnerability2021-11-03
Microsoft
Windows Common Log File System Driver Elevation of Privilege Vulnerability2019-09-10

🕵️Threat Intelligence

8
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys2022-02-23
Trendmicro
September Patch Tuesday: RDP Vulns and Zero-Days2019-09-11
Trendmicro
September Patch Tuesday: RDP Vulns and Zero-Days2019-09-11
Krebs
Patch Tuesday, September 2019 Edition2019-09-10
Tenable
Microsoft's September 2019 Patch Tuesday: Tenable Roundup2019-09-10
CVE-2019-1214 — Microsoft Windows vulnerability | cvebase