CVE-2019-1129

HIGH KEV RANSOMWARE

Windows AppXSVC - Privilege Escalation

Title source: llm

Description

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1130.

Scores

CVSS v3 7.8
EPSS 0.0207
EPSS Percentile 84.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2022-03-15
VulnCheck KEV 2022-03-15
InTheWild.io 2022-03-15
ENISA EUVD EUVD-2019-9706
Ransomware Use Confirmed
CWE
CWE-59
Status published
Products (8)
microsoft/windows_10_1703 (2 CPE variants)
microsoft/windows_10_1709 (3 CPE variants)
microsoft/windows_10_1803 (3 CPE variants)
microsoft/windows_10_1809 (3 CPE variants)
microsoft/windows_10_1903 (3 CPE variants)
microsoft/windows_server_1803
microsoft/windows_server_1903
microsoft/windows_server_2019
Published Jul 15, 2019
KEV Added Mar 15, 2022
Tracked Since Feb 18, 2026