CVE-2019-1130
KEV ransomwaremassLocal Privilege Escalation in Microsoft Windows AppX Deployment Service
CISA: Microsoft Windows AppX Deployment Service Privilege Escalation Vulnerability
An elevation of privilege vulnerability exists in the Windows AppX Deployment Service (AppXSVC), which improperly handles hard links when working with deployed app packages (CWE-59, link following). A local attacker with limited user privileges can exploit the mishandled hard-link handling to execute code with elevated rights, gaining high-impact confidentiality, integrity, and availability control over the host. Affected systems are Windows 10 versions 1507 through 1903, Windows 8.1, Windows RT 8.1, Windows Server 2012, Windows Server 1803, and Windows Server 1903. The flaw is exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-23 with known ransomware use, and EPSS estimates a 2.3% probability of exploitation within the next 30 days. No public proof-of-concept is known; attackers appear to use working exploits not publicly released.
What to do: Apply Microsoft's security updates for the affected Windows versions per vendor instructions (the fixes shipped in the July 2019 Patch Tuesday updates), or upgrade hosts beyond Windows 10 1507–1903/Server 2012-era builds. Prioritize patching workstations and servers in ransomware-exposed environments, since this flaw is listed in CISA's KEV with known ransomware use and is typically chained with other vulnerabilities to escalate from an initial foothold to SYSTEM. Confirm remediation by verifying hosts no longer run unpatched instances of the affected builds.
| microsoft windows 10 1507 | 1507 |
| microsoft windows 10 1607 | 1607 |
| microsoft windows 10 1703 | 1703 |
| microsoft windows 10 1709 | 1709 |
| microsoft windows 10 1803 | 1803 |
| microsoft windows 10 1809 | 1809 |
| microsoft windows 10 1903 | 1903 |
| microsoft windows 8.1 | 8.1 |
| microsoft windows rt 8.1 | 8.1 |
| microsoft windows server 2012 | 2012 |
| microsoft windows server 1803 | 1803 |
| microsoft windows server 1903 | 1903 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows 8.1, windows rt 8.1, windows server 1803, windows server 1903, windows server 2012
- Weakness
- CWE-59
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.