An elevation of privilege vulnerability exists in the way that the Windows Network File System (NFS) handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application. The security update addresses the vulnerability by ensuring the Windows NFS properly handles objects in memory.
History

Fri, 20 Feb 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 10 1507
Microsoft windows Server 2008 R2
Microsoft windows Server 2012 R2
CPEs cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_8.1:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_server_2008_R2:*:*:*:*:*:*:itanium:*
cpe:2.3:o:microsoft:windows_server_2008_R2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft windows 10 1507
Microsoft windows Server 2008 R2
Microsoft windows Server 2012 R2

Tue, 20 May 2025 18:00:00 +0000

Type Values Removed Values Added
Description An elevation of privilege vulnerability exists in the way that the Windows Network File System (NFS) handles objects in memory, aka 'Windows Network File System Elevation of Privilege Vulnerability'. An elevation of privilege vulnerability exists in the way that the Windows Network File System (NFS) handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application. The security update addresses the vulnerability by ensuring the Windows NFS properly handles objects in memory.
Title Windows Network File System Elevation of Privilege Vulnerability
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C'}


cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2025-05-20T17:50:18.692Z

Reserved: 2018-11-26T00:00:00.000Z

Link: CVE-2019-1045

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-06-12T14:29:03.853

Modified: 2025-05-20T18:15:40.387

Link: CVE-2019-1045

cve-icon Redhat

No data.