CVE-2019-0732 EXPLOIT
7.8
HIGH · CVSS 3.0 · EPSS 3.8% (pctl 90)
Patch early
A public exploit exists.
Description
A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Windows improperly handles calls to the LUAFV driver (luafv.sys), aka 'Windows Security Feature Bypass Vulnerability'.
Scoring
| CVSS | 7.8 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.78% — more likely to be exploited than 90% of all CVEs |
| Weakness | CWE-863 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-04-09 |
| Last modified | 2026-06-17 |
Affected (8)
| Vendor | Product |
|---|---|
| microsoft | windows 10 |
| microsoft | windows 7 |
| microsoft | windows 8.1 |
| microsoft | windows rt 8.1 |
| microsoft | windows server 2008 |
| microsoft | windows server 2012 |
| microsoft | windows server 2016 |
| microsoft | windows server 2019 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Windows 10 1809 - LUAFV NtSetCachedSigningLevel Device Guard Bypass | 2019-04-16 |
References
- http://packetstormsecurity.com/files/152536/Microsoft-Windows-LUAFV-NtSetCachedSigningLevel-Device-Guard-Bypass.html
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0732
- https://www.exploit-db.com/exploits/46716/
- http://packetstormsecurity.com/files/152536/Microsoft-Windows-LUAFV-NtSetCachedSigningLevel-Device-Guard-Bypass.html
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0732
- https://www.exploit-db.com/exploits/46716/
→ the Explorer · watch your stack · NVD