ZeroHour

CVE-2019-1129

KEV ransomwaremass

Local Privilege Escalation in Windows AppX Deployment Service (AppXSVC)

CISA: Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
2%p77
Published
()
KEV added
AI analysis

An elevation of privilege flaw exists in the Windows AppX Deployment Service (AppXSVC), which improperly handles hard links (CWE-59, improper link resolution before file access), causing file operations to target an unintended path. A local attacker with limited privileges can trigger the mishandled hard-link processing without user interaction and elevate to higher privileges, gaining broad read, write, and modify capabilities at an elevated context. The issue, rated 7.8 High with a local attack vector, affects Windows 10 versions 1703 through 1903 and Windows Server 1803, 1903, and 2019. It was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-15 with known ransomware use, indicating exploitation in the wild, though no public proof-of-concept is known. Defenders should prioritize remediation given its documented role in ransomware operations.

What to do: Apply Microsoft's security updates for each affected Windows build per vendor instructions, as required by CISA's KEV catalog. Because Windows 10 1703–1903 and Windows Server 1803/1903 builds are now out of support, upgrade those systems to a currently supported, fully patched Windows release. Given known ransomware use, prioritize user-facing and internet-reachable endpoints in patch triage and inventory your environment for any remaining legacy builds.

Affected
microsoft Windows 101703
microsoft Windows 101709
microsoft Windows 101803
microsoft Windows 101809
microsoft Windows 101903
microsoft Windows Server1803 (Semi-Annual Channel)
microsoft Windows Server1903 (Semi-Annual Channel)
microsoft Windows Server2019
Estimated exposure
mass≈100M+ endpoints at time of disclosure (affected builds spanned the then-current Windows 10 and Windows Server 2019/1803/1903 installed base); residual… — Windows 10 held dominant desktop market share and the listed semi-annual channel builds were the then-current supported versions, so the flaw plausibly touched most of the several-hundred-million-device Windows 10 fleet when disclosed in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1130.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows server 1803, windows server 1903, windows server 2019
Weakness
CWE-59
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.