CVE-2019-1405
KEV
🔴 Łataj teraz
Luka w Windows UPnP umożliwia eskalację uprawnień przez nieprawidłowe tworzenie obiektów COM.
CVSS
7.8
EPSS
29.9%
Exploit
weaponized
Vendor
microsoft
Opis źródłowy (NVD)
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'.
privilege-escalation
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.8 |
| CISA KEV (aktywnie wykorzystywane) | Tak |
| FIRST EPSS (prawdopodobieństwo exploita) | 29.9% |
| Opublikowano (NVD) | 2019-11-12 19:15:13 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-12 05:17:24 UTC |
Referencje
- http://packetstormsecurity.com/files/155723/Microsoft-UPnP-Local-Privilege-Elevation.html (secure@microsoft.com) [Third Party Advisory, VDB Entry]
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1405 (secure@microsoft.com) [Patch, Vendor Advisory]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-1405 (134c704f-9b21-4f2e-91b3-4a467353bcc0) [US Government Resource]