Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-0574. PoCs published by Google Security Research.
AI-analyzed exploit summary The writeup describes an Elevation of Privilege (EoP) vulnerability in the Windows Data Sharing Service (DSSVC) due to flawed implementation of the MoveFileInheritSecurity method, which allows arbitrary file writes and ACL manipulation via hardlink attacks. The author provides a detailed technical analysis and references a Proof of Concept (PoC) available as a C# project.
Description
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Service Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers. This CVE ID is unique from CVE-2019-0571, CVE-2019-0572, CVE-2019-0573.
Exploits (1)
The writeup describes an Elevation of Privilege (EoP) vulnerability in the Windows Data Sharing Service (DSSVC) due to flawed implementation of the MoveFileInheritSecurity method, which allows arbitrary file writes and ACL manipulation via hardlink attacks. The author provides a detailed technical analysis and references a Proof of Concept (PoC) available as a C# project.
References (3)
Scores
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H