ZeroHour

CVE-2019-1253

KEV ransomwaremass

Local Privilege Escalation in Microsoft Windows AppX Deployment Server

CISA: Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
12%p96
Published
()
KEV added
AI analysis

CVE-2019-1253 is an elevation of privilege vulnerability in the Windows AppX Deployment Server, which improperly handles junctions (reparse-point links, mapped to CWE-59), allowing file operations to be redirected to attacker-controlled locations. Exploitation is local: an attacker must first gain low-privileged code execution on the victim system, then abuse the flawed junction handling to escalate privileges. A successful attack yields elevated (administrative/SYSTEM-level) rights with high impact on confidentiality, integrity, and availability, reflected in the CVSS 3.1 score of 7.8. Affected systems are Windows 10 versions 1703, 1709, 1803, 1809, and 1903, and Windows Server 1803, 1903, and 2019. The flaw is being exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-15 with confirmed ransomware use — and EPSS puts the probability of exploitation in the next 30 days at 11.6% (96th percentile).

What to do: Apply Microsoft's security updates per vendor instructions immediately — patching is a CISA KEV required action and the flaw has confirmed ransomware use, so prioritize endpoints and servers. Because the affected builds (Windows 10 1703–1903 and Windows Server 1803/1903/2019) are legacy, verify each host is on a servicing channel still receiving the update or migrate to a supported build. Since exploitation requires prior low-privileged code execution, pair patching with endpoint detection coverage to catch initial-access activity before the privilege escalation step.

Affected
Microsoft Windows 101703
Microsoft Windows 101709
Microsoft Windows 101803
Microsoft Windows 101809
Microsoft Windows 101903
Microsoft Windows Server1803
Microsoft Windows Server1903
Microsoft Windows Server2019
Estimated exposure
mass≈100M+ endpoints and servers (these Windows 10/Server branches accounted for a large share of Microsoft's >1B Windows 10 install base at disclosure) — Estimated from Microsoft's Windows 10 installed base exceeding one billion devices, with builds 1703 through 1903 being mainstream serviced branches at the time of disclosure and legacy builds still common on enterprise endpoints and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1215, CVE-2019-1278, CVE-2019-1303.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows server 1803, windows server 1903, windows server 2019
Weakness
CWE-59
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.