Executive brief
An elevation of privilege vulnerability exists in the Microsoft Windows AppX Deployment Service (AppXSVC) due to improper handling of hard links. A local attacker could exploit this by following links to gain elevated process execution context on the affected system.
Affected products
- Microsoft Windows 10 1703, 1709, 1803, 1809, 1903
- Microsoft Windows Server 2016 1803, 1903
- Microsoft Windows Server 2019 -
Timeline
- 2019-07-15: disclosed: NVD Published Date
- 2019-07-15: patched: Microsoft released security updates
- 2022-03-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-15: exploited: Reported as exploited in the wild per CISA KEV entry