⚠ Actively exploited in ransomware campaigns
This vulnerability is on the CISA Known Exploited Vulnerabilities list and has been used in known ransomware attacks. CISA required action: Apply updates per vendor instructions.. Due date: 2022-06-13.

CVE-2019-1130

6 documents6 sources
7.8
CVSS
HIGH
EPSS1.9%(83th)
CISA KEVExploited in WildRansomware Use
CISA Required Action: Apply updates per vendor instructions.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129.

🔴Vulnerability Details

3
GHSA
GHSA-gxfx-4m5q-qcqf: An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of2022-05-24
CVEList
CVE-2019-1130: An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of2019-07-29
VulnCheck
Microsoft Windows AppX Deployment Service Privilege Escalation Vulnerability2019

📋Vendor Advisories

2
CISA
Microsoft Windows AppX Deployment Service Privilege Escalation Vulnerability2022-05-23
Microsoft
Windows Elevation of Privilege Vulnerability2019-07-09
CVE-2019-1130 (HIGH CVSS 7.8) | An elevation of privilege vulnerabi | cvebase.io