CVE-2019-1388
Microsoft Windows Certificate Dialog Privilege Escalation Vulnerability
- Published
- Nov 12, 2019
- Updated
- Oct 21, 2025
- Assigning CNA
- microsoft
- Evidence observed
- Apr 7, 2023
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HLow · next 30 days
- Percentile
- 94.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Certificate Dialog Elevation of Privilege Vulnerability'.
Sources
6CVE-2019-1388 Lab Analysis: Documented local privilege escalation via Windows UAC certificate dialogs on Windows 7.
CVE-2019-1388 UAC提权 (nt authority\system)
Proof-of-concept exploit for CVE-2019-1388, a Windows UAC bypass privilege escalation vulnerability. Demonstrates exploitation of the Windows Installer service to gain elevated privileges.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.