ZeroHour

CVE-2019-1064

KEV ransomwaremass

Local Privilege Escalation in Microsoft Windows AppX Deployment Service

CISA: Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
7%p94
Published
()
KEV added
AI analysis

Microsoft Windows AppX Deployment Service (AppXSVC) improperly handles hard links, creating an elevation of privilege vulnerability tracked as CVE-2019-1064 (CWE-59, link following). The flaw is triggered when a local attacker who is already able to log on to an affected system runs a specially crafted application. Successful exploitation allows the attacker to run processes in an elevated context, then install programs and view, change, or delete data, effectively taking control of the affected system. Affected products span Windows 10 versions 1607, 1703, 1709, 1803, 1809, and 1903, plus Windows Server 1709, 1803, 1903, 2016, and 2019. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-15) with known ransomware use, so it is being actively exploited in the wild.

What to do: Apply Microsoft's security update for all affected Windows 10 and Windows Server builds per vendor instructions, as required by CISA's KEV catalog, and upgrade any systems on builds 1607-1903 that no longer receive updates to a supported Windows release. Because exploitation requires local logon, prioritize patching multi-user workstations, RDP-exposed servers, and systems at ransomware risk, and confirm remediation by checking that the OS build includes the AppXSVC hard-link fix.

Affected
microsoft Windows 101607
microsoft Windows 101703
microsoft Windows 101709
microsoft Windows 101803
microsoft Windows 101809
microsoft Windows 101903
microsoft Windows Server1709
microsoft Windows Server1803
microsoft Windows Server1903
microsoft Windows Server 2016all versions in the affected range
microsoft Windows Server 2019all versions in the affected range
Estimated exposure
masshundreds of millions of Windows 10 and Windows Server installations worldwide — Windows 10 ran on roughly a billion devices at the time of disclosure, and the affected builds (1607 through 1903) represented a large share of the installed desktop and server base, so the plausibly affected population far exceeds the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install programs; view, change or delete data. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. The security update addresses the vulnerability by correcting how Windows AppX Deployment Service handles hard links.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows server 1709, windows server 1803, windows server 1903, windows server 2016, windows server 2019
Weakness
CWE-59
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news