Stating about this vulnerability, CVE-2019-1458, in an advisory, Microsoft said,
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.Exploiting the flaw required an attacker to log on to the system and run a maliciously crafted application.
What’s more troubling with this bug is that the attackers already started exploiting this flaw before a patch.
According to Kaspersky, who discovered this zero-day, elaborated in their blog post, that this bug possibly came under exploit together with another zero-day flaw in Google Chrome (CVE-2019-13720) that the researchers discovered last month.
The exploit for Google Chrome embeds a 0-day EoP exploit (CVE-2019-1458) that is used to gain higher privileges on the infected machine as well as escaping the Chrome process sandbox.
Collectively, the software receiving security updates this month include Microsoft Windows, Skype for Business, Visual Studio, SQL Server, Microsoft Office and Microsoft Office Services and Web Apps, and Internet Explorer.
In November Microsoft again fixed an actively exploited zero-day bug.
Let us know your thoughts in the comments.