CVE-2019-1385
KEV
🔴 Łataj teraz
Luka w Windows AppX Deployment Extensions umożliwia eskalację uprawnień do plików systemowych.
CVSS
7.8
EPSS
3.6%
Exploit
weaponized
Vendor
microsoft
Opis źródłowy (NVD)
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'.
privilege-escalation
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.8 |
| CISA KEV (aktywnie wykorzystywane) | Tak |
| FIRST EPSS (prawdopodobieństwo exploita) | 3.6% |
| Opublikowano (NVD) | 2019-11-12 19:15:12 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-12 05:17:23 UTC |
Referencje
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1385 (secure@microsoft.com) [Patch, Vendor Advisory]
- https://www.zerodayinitiative.com/advisories/ZDI-19-979/ (secure@microsoft.com) [Third Party Advisory]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-1385 (134c704f-9b21-4f2e-91b3-4a467353bcc0) [US Government Resource]