CVE-2019-1253
KEV ransomwaremassLocal Privilege Escalation in Microsoft Windows AppX Deployment Server
CISA: Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability
CVE-2019-1253 is an elevation of privilege vulnerability in the Windows AppX Deployment Server, which improperly handles junctions (reparse-point links, mapped to CWE-59), allowing file operations to be redirected to attacker-controlled locations. Exploitation is local: an attacker must first gain low-privileged code execution on the victim system, then abuse the flawed junction handling to escalate privileges. A successful attack yields elevated (administrative/SYSTEM-level) rights with high impact on confidentiality, integrity, and availability, reflected in the CVSS 3.1 score of 7.8. Affected systems are Windows 10 versions 1703, 1709, 1803, 1809, and 1903, and Windows Server 1803, 1903, and 2019. The flaw is being exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-15 with confirmed ransomware use — and EPSS puts the probability of exploitation in the next 30 days at 11.6% (96th percentile).
What to do: Apply Microsoft's security updates per vendor instructions immediately — patching is a CISA KEV required action and the flaw has confirmed ransomware use, so prioritize endpoints and servers. Because the affected builds (Windows 10 1703–1903 and Windows Server 1803/1903/2019) are legacy, verify each host is on a servicing channel still receiving the update or migrate to a supported build. Since exploitation requires prior low-privileged code execution, pair patching with endpoint detection coverage to catch initial-access activity before the privilege escalation step.
| Microsoft Windows 10 | 1703 |
| Microsoft Windows 10 | 1709 |
| Microsoft Windows 10 | 1803 |
| Microsoft Windows 10 | 1809 |
| Microsoft Windows 10 | 1903 |
| Microsoft Windows Server | 1803 |
| Microsoft Windows Server | 1903 |
| Microsoft Windows Server | 2019 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1215, CVE-2019-1278, CVE-2019-1303.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows server 1803, windows server 1903, windows server 2019
- Weakness
- CWE-59
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.