ZeroHour

CVE-2019-0841

KEV ransomware PoC ×2mass

Local Privilege Escalation via Hard-Link Flaw in Windows AppX Deployment Service

CISA: Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
41%p99
Published
()
KEV added
AI analysis

CVE-2019-0841 is a local privilege escalation flaw in the Windows AppX Deployment Service (AppXSVC), which handles deployment of packaged (AppX) applications. The service improperly handles hard links (CWE-59), letting a local attacker manipulate hard links so that AppXSVC performs file operations in protected locations with elevated rights. A successful exploit allows the attacker to run processes in an elevated context — effectively administrative/SYSTEM privileges — which ransomware operators have used in chained attacks. Any unpatched Microsoft Windows system is potentially affected; the available data lists only 'Microsoft Windows' without specific version ranges, so defenders should consult Microsoft's advisory for exact affected releases. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-15 with known ransomware use, and EPSS assigns a 41.4% probability of exploitation within 30 days (99th percentile), although no public proof-of-concept is catalogued.

What to do: Apply Microsoft's Windows cumulative updates per vendor instructions as the KEV required action, prioritizing systems where users can log on locally, since exploitation requires local access; the fix shipped in Microsoft's April 2019 security release, so confirm no hosts remain on older builds. Because ransomware operators chain this local privilege escalation, verify patch status across the estate with your inventory tooling and monitor for unexpected elevation or hard-link manipulation on AppXSVC as interim risk reduction.

Affected
Microsoft Windows
Estimated exposure
masshundreds of millions of Windows endpoints potentially in scope (Windows runs on 1B+ active devices, ~70% desktop share), limited to unpatched systems — Windows' install base of over a billion active devices and roughly 70% desktop OS market share means nearly all Windows deployments that have not applied the vendor fix are theoretically exposed, since AppXSVC is a core Windows component.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows server 2016, windows server 2019
Weakness
CWE-59
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news