← Back to SOC feed Coverage →

detect-cve-2019-0863-AngryPolarBearBug2-exploit

kql MEDIUM Azure-Sentinel
DeviceProcessEvents
backdoorexploithuntingmicrosoftofficial
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Azure-Sentinel →
Retrieved: 2026-05-24T11:00:00Z · Confidence: medium

Hunt Hypothesis

Adversaries may exploit the AngryPolarBearBug2 vulnerability in Azure environments to escalate privileges and maintain persistence. SOC teams should proactively hunt for this behavior to identify and mitigate potential compromise from advanced persistent threats leveraging this unpatched vulnerability.

KQL Query

//Find possible CVE-2019-0863 exploitation
DeviceProcessEvents 
| where FileName =~ "schtasks.exe"
| where ProcessCommandLine contains "Windows Error Reporting"
and ProcessCommandLine contains "/run"

Analytic Rule Definition

id: 8cc1b312-46c6-4f41-bc66-f8a12fac7e67
name: detect-cve-2019-0863-AngryPolarBearBug2-exploit
description: |
  This query was originally published in the threat analytics report, May 2019 0-day disclosures.
  In May and June of 2019, a security researcher with the online alias, SandboxEscaper, discovered and published several elevation-of-privilege vulnerabilities on Github. The researcher included proofs-of-concept demonstrating how to exploit these vulnerabilities.
  Patches and more information about each vulnerability are available below:
  1. CVE-2019-0863 | Windows Error Reporting Elevation of Privilege Vulnerability
  2. CVE-2019-1069 | Task Scheduler Elevation of Privilege Vulnerability
  3. CVE-2019-1053 | Windows Shell Elevation of Privilege Vulnerability
  4. CVE-2019-1064 | Windows Elevation of Privilege Vulnerability
  5. CVE-2019-0973 | Windows Installer Elevation of Privilege Vulnerability
  6. CVE-2019-1129 | Windows Elevation of Privilege Vulnerability
  This query locates possible activity that exploits CVE-2019-0863 (also known as AngryPolarBearBug2), the first vulnerability listed above.
  Reference - https://threatpost.com/sandboxescaper-more-exploits-ie-zero-day/145010/
requiredDataConnectors:
- connectorId: MicrosoftThreatProtection
  dataTypes:
  - DeviceProcessEvents
tactics:
- Privilege escalation
query: |
  //Find possible CVE-2019-0863 exploitation
  DeviceProcessEvents 
  | where FileName =~ "schtasks.exe"
  | where ProcessCommandLine contains "Windows Error Reporting"
  and ProcessCommandLine contains "/run"

Required Data Sources

Sentinel TableNotes
DeviceProcessEventsEnsure this data connector is enabled

MITRE ATT&CK Context

References

False Positive Guidance

Original source: https://github.com/Azure/Azure-Sentinel/blob/main/Hunting Queries/Microsoft 365 Defender/Privilege escalation/detect-cve-2019-0863-AngryPolarBearBug2-exploit.yaml