ZeroHour

CVE-2019-1405

KEV ransomwaremass

Local Privilege Escalation in Microsoft Windows UPnP Service

CISA: Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
30%p98
Published
()
KEV added
AI analysis

CVE-2019-1405 is a local privilege escalation flaw in the Microsoft Windows Universal Plug and Play (UPnP) service, caused by the service improperly allowing COM object creation. A local attacker with limited privileges, or an attacker who has already gained a low-privileged foothold (for example via another vulnerability), can trigger the flaw by creating a COM object through the UPnP service. Successful exploitation grants the attacker elevated privileges on the host, which in ransomware campaigns is used to move from a foothold to full control of the machine. All deployments of the affected Microsoft Windows products are in scope; specific version ranges are defined by Microsoft's security-update guidance rather than the alert data. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-15) with known ransomware use, and EPSS assigns it a high ~29.9% chance of exploitation in the next 30 days.

What to do: Apply the Windows security updates from Microsoft per vendor instructions on all endpoints, prioritizing user workstations and jump hosts where attackers gain initial footholds and escalate to SYSTEM. Because the flaw is a local escalation actively used in ransomware chains, combine patching with review of lateral-movement indicators (unusual service or COM object activity) and confirm hosts are running a cumulative update that includes the UPnP service fix.

Affected
Microsoft Windows
Estimated exposure
masson the order of hundreds of millions to 1+ billion Windows devices potentially affected (Windows install base) — Windows runs on roughly a billion or more consumer and enterprise devices, and as a local privilege escalation the flaw is relevant to effectively every unpatched Windows endpoint, so exposure is estimated from the overall Windows install…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows 7, windows 8.1, windows rt 8.1, windows server 1803, windows server 1903, windows server 2008
Weakness
CWE-269
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news