Executive brief
An elevation of privilege vulnerability exists in the Microsoft Windows Universal Plug and Play (UPnP) service due to improper handling of COM object creation. A local attacker could exploit this to execute arbitrary code with elevated system privileges.
Affected products
- Microsoft Windows 10 1507, 1607, 1709, 1803, 1809, 1903
- Microsoft Windows 7 SP1
- Microsoft Windows 8.1
- Microsoft Windows RT 8.1
- Microsoft Windows Server 2008 SP2, R2 SP1
- Microsoft Windows Server 2012 Gold, R2
- Microsoft Windows Server 2016 Gold, 1803, 1903
- Microsoft Windows Server 2019
Timeline
- 2019-11-12: advisory: MSRC advisory published
- 2022-03-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-15: exploited: Confirmed exploited in the wild per CISA KEV catalog