An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0797.
https://www.tenable.com/blog/cve-2020-0674-internet-explorer-remote-code-execution-vulnerability-exploited-in-the-wild
https://www.tenable.com/blog/cve-2019-1367-critical-internet-explorer-memory-corruption-vulnerability-exploited-in-the-wild
https://www.tenable.com/blog/use-after-free-vulnerability-in-google-chrome-exploited-in-the-wild-cve-2019-5786
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0808
http://packetstormsecurity.com/files/157616/Microsoft-Windows-NtUserMNDragOver-Local-Privilege-Escalation.html
Source: Mitre, NVD
Published: 2019-04-09
Updated: 2025-04-04
Known Exploited Vulnerability (KEV)
Base Score: 7.2
Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C
Severity: High
Base Score: 7.8
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.51367