Executive brief
An elevation of privilege vulnerability exists in the Microsoft Windows AppX Deployment Server due to improper handling of junctions. An attacker with local execution privileges can exploit this to gain elevated system permissions.
Affected products
- Microsoft Windows 10 1703, 1709, 1803, 1809, 1903
- Microsoft Windows Server 2019
- Microsoft Windows Server 1803, 1903
Timeline
- 2022-03-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-15: disclosed
- 2022-03-15: exploited: Reported as exploited in the wild.