ZeroHour

CVE-2019-1130

KEV ransomwaremass

Local Privilege Escalation in Microsoft Windows AppX Deployment Service

CISA: Microsoft Windows AppX Deployment Service Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
2%p82
Published
()
KEV added
AI analysis

An elevation of privilege vulnerability exists in the Windows AppX Deployment Service (AppXSVC), which improperly handles hard links when working with deployed app packages (CWE-59, link following). A local attacker with limited user privileges can exploit the mishandled hard-link handling to execute code with elevated rights, gaining high-impact confidentiality, integrity, and availability control over the host. Affected systems are Windows 10 versions 1507 through 1903, Windows 8.1, Windows RT 8.1, Windows Server 2012, Windows Server 1803, and Windows Server 1903. The flaw is exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-23 with known ransomware use, and EPSS estimates a 2.3% probability of exploitation within the next 30 days. No public proof-of-concept is known; attackers appear to use working exploits not publicly released.

What to do: Apply Microsoft's security updates for the affected Windows versions per vendor instructions (the fixes shipped in the July 2019 Patch Tuesday updates), or upgrade hosts beyond Windows 10 1507–1903/Server 2012-era builds. Prioritize patching workstations and servers in ransomware-exposed environments, since this flaw is listed in CISA's KEV with known ransomware use and is typically chained with other vulnerabilities to escalate from an initial foothold to SYSTEM. Confirm remediation by verifying hosts no longer run unpatched instances of the affected builds.

Affected
microsoft windows 10 15071507
microsoft windows 10 16071607
microsoft windows 10 17031703
microsoft windows 10 17091709
microsoft windows 10 18031803
microsoft windows 10 18091809
microsoft windows 10 19031903
microsoft windows 8.18.1
microsoft windows rt 8.18.1
microsoft windows server 20122012
microsoft windows server 18031803
microsoft windows server 19031903
Estimated exposure
mass≈800M–1B Windows installations (Windows 10 alone was reported on roughly 900 million devices around the time of disclosure, plus Windows 8.1/RT 8.1 and Server… — The affected range spans essentially the entire Windows 10 installed base at disclosure plus Windows 8.1 and Windows Server 2012, and Windows is the dominant desktop/server OS, so plausible exposure is measured in hundreds of millions of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows 8.1, windows rt 8.1, windows server 1803, windows server 1903, windows server 2012
Weakness
CWE-59
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.