CVE-2019-1129
KEV ransomwaremassLocal Privilege Escalation in Windows AppX Deployment Service (AppXSVC)
CISA: Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability
An elevation of privilege flaw exists in the Windows AppX Deployment Service (AppXSVC), which improperly handles hard links (CWE-59, improper link resolution before file access), causing file operations to target an unintended path. A local attacker with limited privileges can trigger the mishandled hard-link processing without user interaction and elevate to higher privileges, gaining broad read, write, and modify capabilities at an elevated context. The issue, rated 7.8 High with a local attack vector, affects Windows 10 versions 1703 through 1903 and Windows Server 1803, 1903, and 2019. It was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-15 with known ransomware use, indicating exploitation in the wild, though no public proof-of-concept is known. Defenders should prioritize remediation given its documented role in ransomware operations.
What to do: Apply Microsoft's security updates for each affected Windows build per vendor instructions, as required by CISA's KEV catalog. Because Windows 10 1703–1903 and Windows Server 1803/1903 builds are now out of support, upgrade those systems to a currently supported, fully patched Windows release. Given known ransomware use, prioritize user-facing and internet-reachable endpoints in patch triage and inventory your environment for any remaining legacy builds.
| microsoft Windows 10 | 1703 |
| microsoft Windows 10 | 1709 |
| microsoft Windows 10 | 1803 |
| microsoft Windows 10 | 1809 |
| microsoft Windows 10 | 1903 |
| microsoft Windows Server | 1803 (Semi-Annual Channel) |
| microsoft Windows Server | 1903 (Semi-Annual Channel) |
| microsoft Windows Server | 2019 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1130.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows server 1803, windows server 1903, windows server 2019
- Weakness
- CWE-59
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.