Microsoft today issued its April batch of security fixes, which patches 74 vulnerabilities including two Windows zero-days under active attack.
CVE-2019-0803 and CVE-2019-0859 both patch Windows elevation of privilege bugs found exploited in the wild. Microsoft describes both patches in a similar manner: In short, a vulnerability exists when the Win32k component doesn’t properly handle objects in memory. An attacker could exploit this to run malicious code in kernel mode and install programs; view, change, or delete data; or create a new account with full user rights.
If this sounds familiar, it’s likely because last month’s Patch Tuesday also addressed two zero-day elevation-of-privilege vulnerabilities in Windows. Both were rated Important in severity, enabling an attacker with system access to increase their privileges and take over the system.