CVE-2019-1385
KEV ransomwaremassLocal Privilege Escalation in Windows AppX Deployment Extensions
CISA: Microsoft Windows AppX Deployment Extensions Privilege Escalation Vulnerability
CVE-2019-1385 is an elevation-of-privilege flaw in the Windows AppX Deployment Extensions, which improperly manage privileges (CWE-59, a link-fault weakness) and allow access to system files normally reserved for higher-privileged users. An authenticated attacker with a low-privilege account must run a specially crafted application on a vulnerable machine; no user interaction is required. Successful exploitation yields elevated privileges on the local system, typically SYSTEM-level access, which can enable full compromise of the host and serve as a step in broader attack chains. Affected systems are Windows 10 versions 1709, 1803, 1809, and 1903, plus Windows Server 2016 and Windows Server 2019. The flaw was fixed in Microsoft's November 2019 Patch Tuesday, and despite no known public proof-of-concept it has been added to the CISA KEV catalog (May 2022) with known ransomware use, so active exploitation is established.
What to do: Apply the November 2019 Microsoft cumulative security updates (or any later cumulative update) on all affected Windows 10 and Windows Server hosts, prioritizing internet-facing and domain servers running Server 2016/2019 given the known ransomware use and KEV listing. Systems on end-of-service builds such as 1709, 1803, and 1903 should be upgraded to a supported Windows 10 release where extended updates are not in place. After patching, verify the installed OS build in your asset inventory, and restrict interactive logon rights for unprivileged users on servers as defense-in-depth.
| microsoft Windows 10 | 1709, 1803, 1809, 1903 |
| microsoft Windows Server | 2016, 2019 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows server 2016, windows server 2019
- Weakness
- CWE-59
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H