← back
CVE-2019-0943

Windows ALPC Elevation of Privilege Vulnerability

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 3.2%
from disclosure to weapon12 days
Published on NVDJun 12
1st PoC+12d
exploitation probability
3.2%top 13% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control over an affected system. The update addresses the vulnerability by correcting how Windows handles calls to ALPC.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.