Junglewise Threat Intelligence

CVE-2019-1064: Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability

CVE-2019-1064 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-03-15

Technologies: Microsoft Windows, Microsoft Windows Server 2019, Microsoft Windows 10, Microsoft Windows Server 2016. Vendors: Microsoft.

Executive brief

An elevation of privilege vulnerability in the Microsoft Windows AppX Deployment Service (AppXSVC) occurs when the service improperly handles hard links. A local attacker can exploit this by running a specially crafted application to execute processes in an elevated context, potentially gaining full control of the affected system.

Affected products

  • Microsoft Windows 10 1607, 1703, 1709, 1803, 1809, 1903
  • Microsoft Windows Server 2016 - (Base), 1803, 1903
  • Microsoft Windows Server 2019 - (Base)

Timeline

  • 2019-05-14: patched: Microsoft released security updates to address the vulnerability.
  • 2022-03-15: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.

Related threats