ZeroHour

CVE-2019-1385

KEV ransomwaremass

Local Privilege Escalation in Windows AppX Deployment Extensions

CISA: Microsoft Windows AppX Deployment Extensions Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
4%p89
Published
()
KEV added
AI analysis

CVE-2019-1385 is an elevation-of-privilege flaw in the Windows AppX Deployment Extensions, which improperly manage privileges (CWE-59, a link-fault weakness) and allow access to system files normally reserved for higher-privileged users. An authenticated attacker with a low-privilege account must run a specially crafted application on a vulnerable machine; no user interaction is required. Successful exploitation yields elevated privileges on the local system, typically SYSTEM-level access, which can enable full compromise of the host and serve as a step in broader attack chains. Affected systems are Windows 10 versions 1709, 1803, 1809, and 1903, plus Windows Server 2016 and Windows Server 2019. The flaw was fixed in Microsoft's November 2019 Patch Tuesday, and despite no known public proof-of-concept it has been added to the CISA KEV catalog (May 2022) with known ransomware use, so active exploitation is established.

What to do: Apply the November 2019 Microsoft cumulative security updates (or any later cumulative update) on all affected Windows 10 and Windows Server hosts, prioritizing internet-facing and domain servers running Server 2016/2019 given the known ransomware use and KEV listing. Systems on end-of-service builds such as 1709, 1803, and 1903 should be upgraded to a supported Windows 10 release where extended updates are not in place. After patching, verify the installed OS build in your asset inventory, and restrict interactive logon rights for unprivileged users on servers as defense-in-depth.

Affected
microsoft Windows 101709, 1803, 1809, 1903
microsoft Windows Server2016, 2019
Estimated exposure
massmillions of endpoints and servers (legacy Windows 10 1709–1903 builds plus broad Windows Server 2016/2019 deployments) — Windows 10 versions 1709 through 1903 were mainstream builds across a roughly one-billion-device install base through 2019–2020, and Windows Server 2016/2019 remain widely deployed in enterprise environments, so a multi-million-device long…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows server 2016, windows server 2019
Weakness
CWE-59
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news