CVE-2019-0841

HIGH KEV RANSOMWARE

Windows AppX Deployment Service - Privilege Escalation

Title source: llm

Description

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836.

Exploits (9)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/47128
exploitdb WRITEUP
by SandboxEscaper · textlocalwindows
https://www.exploit-db.com/exploits/46976
exploitdb WORKING POC
by SandboxEscaper · textlocalwindows
https://www.exploit-db.com/exploits/46938
exploitdb SUSPICIOUS
by Nabeel Ahmed · textlocalwindows
https://www.exploit-db.com/exploits/46683
nomisec WORKING POC 243 stars
by rogue-kdc · poc
https://github.com/rogue-kdc/CVE-2019-0841
nomisec WORKING POC 59 stars
by 0x00-0x00 · local
https://github.com/0x00-0x00/CVE-2019-0841-BYPASS
nomisec WORKING POC 2 stars
by likekabin · poc
https://github.com/likekabin/CVE-2019-0841
nomisec NO CODE
by mappl3 · poc
https://github.com/mappl3/CVE-2019-0841
metasploit WORKING POC NORMAL
by Nabeel Ahmed, James Forshaw, Shelby Pace · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/appxsvc_hard_link_privesc.rb

Scores

CVSS v3 7.8
EPSS 0.8265
EPSS Percentile 99.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2022-03-15
VulnCheck KEV 2022-03-15
InTheWild.io 2022-03-15
ENISA EUVD EUVD-2019-1592
Ransomware Use Confirmed
CWE
CWE-59
Status published
Products (6)
microsoft/windows_10_1703
microsoft/windows_10_1709
microsoft/windows_10_1803
microsoft/windows_10_1809
microsoft/windows_server_2016 1803
microsoft/windows_server_2019
Published Apr 09, 2019
KEV Added Mar 15, 2022
Tracked Since Feb 18, 2026