Junglewise Threat Intelligence

CVE-2019-1129: Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability

CVE-2019-1129 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-03-15

Technologies: Microsoft Windows, Microsoft Windows Server 2016, Microsoft Windows 10, Microsoft Windows Server 2019. Vendors: Microsoft.

Executive brief

An elevation of privilege vulnerability exists in the Microsoft Windows AppX Deployment Service (AppXSVC) due to improper handling of hard links. A local attacker could exploit this by following links to gain elevated process execution context on the affected system.

Affected products

  • Microsoft Windows 10 1703, 1709, 1803, 1809, 1903
  • Microsoft Windows Server 2016 1803, 1903
  • Microsoft Windows Server 2019 -

Timeline

  • 2019-07-15: disclosed: NVD Published Date
  • 2019-07-15: patched: Microsoft released security updates
  • 2022-03-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-15: exploited: Reported as exploited in the wild per CISA KEV entry

Related threats