Junglewise Threat Intelligence

CVE-2019-1385: Microsoft Windows AppX Deployment Extensions Privilege Escalation Vulnerability

CVE-2019-1385 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-05-23

Technologies: Microsoft Windows, Microsoft Windows 10, Microsoft Windows Server 2016, Microsoft Windows Server 2019. Vendors: Microsoft.

Executive brief

A privilege escalation vulnerability in Windows AppX Deployment Extensions occurs when the service improperly manages privileges, specifically involving improper link resolution (CWE-59). An authenticated attacker can exploit this by running a specially crafted application to gain unauthorized access to system files and elevate their privileges.

Affected products

  • Microsoft Windows 10 1709, 1803, 1809, 1903
  • Microsoft Windows Server 2016 1803, 1903
  • Microsoft Windows Server 2019 -

Timeline

  • 2019-11-12: disclosed: NVD Published Date
  • 2019-11-12: patched: Microsoft released security updates to address the vulnerability.
  • 2022-05-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-05-23: exploited: Reported as exploited in the wild.

Related threats