Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-0572. PoCs published by Google Security Research.
AI-analyzed exploit summary The exploit leverages a hard link vulnerability in the Data Sharing Service (DSSVC) on Windows 10 1803/1809, allowing a user to open arbitrary files with SYSTEM privileges by manipulating file hard links. The PoC demonstrates arbitrary file write access via DSOpenSharedFile, bypassing path verification checks.
Description
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Service Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers. This CVE ID is unique from CVE-2019-0571, CVE-2019-0573, CVE-2019-0574.
Exploits (1)
The exploit leverages a hard link vulnerability in the Data Sharing Service (DSSVC) on Windows 10 1803/1809, allowing a user to open arbitrary files with SYSTEM privileges by manipulating file hard links. The PoC demonstrates arbitrary file write access via DSOpenSharedFile, bypassing path verification checks.
References (3)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H