CVE-2019-1064
KEV ransomwaremassLocal Privilege Escalation in Microsoft Windows AppX Deployment Service
CISA: Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability
Microsoft Windows AppX Deployment Service (AppXSVC) improperly handles hard links, creating an elevation of privilege vulnerability tracked as CVE-2019-1064 (CWE-59, link following). The flaw is triggered when a local attacker who is already able to log on to an affected system runs a specially crafted application. Successful exploitation allows the attacker to run processes in an elevated context, then install programs and view, change, or delete data, effectively taking control of the affected system. Affected products span Windows 10 versions 1607, 1703, 1709, 1803, 1809, and 1903, plus Windows Server 1709, 1803, 1903, 2016, and 2019. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-15) with known ransomware use, so it is being actively exploited in the wild.
What to do: Apply Microsoft's security update for all affected Windows 10 and Windows Server builds per vendor instructions, as required by CISA's KEV catalog, and upgrade any systems on builds 1607-1903 that no longer receive updates to a supported Windows release. Because exploitation requires local logon, prioritize patching multi-user workstations, RDP-exposed servers, and systems at ransomware risk, and confirm remediation by checking that the OS build includes the AppXSVC hard-link fix.
| microsoft Windows 10 | 1607 |
| microsoft Windows 10 | 1703 |
| microsoft Windows 10 | 1709 |
| microsoft Windows 10 | 1803 |
| microsoft Windows 10 | 1809 |
| microsoft Windows 10 | 1903 |
| microsoft Windows Server | 1709 |
| microsoft Windows Server | 1803 |
| microsoft Windows Server | 1903 |
| microsoft Windows Server 2016 | all versions in the affected range |
| microsoft Windows Server 2019 | all versions in the affected range |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install programs; view, change or delete data. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. The security update addresses the vulnerability by correcting how Windows AppX Deployment Service handles hard links.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows server 1709, windows server 1803, windows server 1903, windows server 2016, windows server 2019
- Weakness
- CWE-59
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H