Executive brief
A privilege escalation vulnerability in the Microsoft Windows AppX Deployment Service (AppXSVC) occurs due to improper handling of hard links. Local attackers can exploit this flaw to execute processes with elevated system privileges.
Affected products
- Microsoft Windows 10 1703, 1709, 1803, 1809
- Microsoft Windows Server 2016 1709, 1803
- Microsoft Windows Server 2019 -
Timeline
- 2019-04-09: advisory: MSRC advisory published (based on CVE ID sequence and reference links)
- 2022-03-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-15: disclosed: Public disclosure date listed in advisory