AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2019-1014

HIGH · CVSS 7 EPSS 0.90% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-06-12 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

Exhibit — Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2019-1014
Severity
HIGH
CVSS
7
EPSS
0.90%
Windows

Original Filing — NVD Description

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. The update addresses this vulnerability by correcting how Win32k handles objects in memory.