Junglewise Threat Intelligence

CVE-2019-0841: Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability

CVE-2019-0841 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-03-15

Technologies: Microsoft Windows Server 2016, Microsoft Windows, Microsoft Windows 10, Microsoft Windows Server 2019. Vendors: Microsoft.

Executive brief

A privilege escalation vulnerability in the Microsoft Windows AppX Deployment Service (AppXSVC) occurs due to improper handling of hard links. Local attackers can exploit this flaw to execute processes with elevated system privileges.

Affected products

  • Microsoft Windows 10 1703, 1709, 1803, 1809
  • Microsoft Windows Server 2016 1709, 1803
  • Microsoft Windows Server 2019 -

Timeline

  • 2019-04-09: advisory: MSRC advisory published (based on CVE ID sequence and reference links)
  • 2022-03-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-15: disclosed: Public disclosure date listed in advisory

Related threats