Junglewise Threat Intelligence

CVE-2019-1130: Microsoft Windows AppX Deployment Service Privilege Escalation Vulnerability

CVE-2019-1130 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-05-23

Technologies: Microsoft Windows Server, Microsoft Windows 10, Microsoft Windows, Microsoft Windows 8.1, Microsoft Windows Rt 8.1. Vendors: Microsoft.

Executive brief

An elevation of privilege vulnerability exists in the Microsoft Windows AppX Deployment Service (AppXSVC) due to improper handling of hard links. A local attacker could exploit this by following links to gain elevated system privileges.

Affected products

  • Microsoft Windows 10 1507, 1607, 1703, 1709, 1803, 1809, 1903
  • Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 1803, 1903
  • Microsoft Windows 8.1
  • Microsoft Windows RT 8.1

Timeline

  • 2019-07-16: disclosed: Initial analysis by NIST
  • 2022-05-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-05-23: exploited: Reported as exploited in the wild

Related threats