CVE-2019-1405
KEV ransomwaremassLocal Privilege Escalation in Microsoft Windows UPnP Service
CISA: Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability
CVE-2019-1405 is a local privilege escalation flaw in the Microsoft Windows Universal Plug and Play (UPnP) service, caused by the service improperly allowing COM object creation. A local attacker with limited privileges, or an attacker who has already gained a low-privileged foothold (for example via another vulnerability), can trigger the flaw by creating a COM object through the UPnP service. Successful exploitation grants the attacker elevated privileges on the host, which in ransomware campaigns is used to move from a foothold to full control of the machine. All deployments of the affected Microsoft Windows products are in scope; specific version ranges are defined by Microsoft's security-update guidance rather than the alert data. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-15) with known ransomware use, and EPSS assigns it a high ~29.9% chance of exploitation in the next 30 days.
What to do: Apply the Windows security updates from Microsoft per vendor instructions on all endpoints, prioritizing user workstations and jump hosts where attackers gain initial footholds and escalate to SYSTEM. Because the flaw is a local escalation actively used in ransomware chains, combine patching with review of lateral-movement indicators (unusual service or COM object activity) and confirm hosts are running a cumulative update that includes the UPnP service fix.
| Microsoft Windows | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows 7, windows 8.1, windows rt 8.1, windows server 1803, windows server 1903, windows server 2008
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H