CVE-2019-0841: high-severity vulnerability in Microsoft Windows
Published · Updated
100Vexday Risk Score
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
ssvc Actcvss 7.8epss 41%
from disclosure to weapon0 days
Published on NVDApr 9
1st PoCApr 5
metasploitApr 9
CISA KEV+1071d
exploitation probability
41%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
15 public exploit(s)
Action required by CISAfederal deadline: 2022-04-05
Apply updates per vendor instructions.
In short
Windows AppX Deployment Service incorrectly handles hard links, allowing an attacker to gain higher-level system privileges. This flaw could let a regular user escalate their access to administrator level.
Technical detail
An improper hard link handling vulnerability in Windows AppXSVC enables local privilege escalation. An attacker with low-level user access can exploit this flaw to gain elevated system privileges by manipulating hard links during the AppX deployment process.
Summary generated and translated by AI from the official description.
The full analysis of this CVE is available in Portuguese →
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
public PoCs found — 15✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/47128exploitdbwww.exploit-db.com/exploits/46683unverifiedexploitdbwww.exploit-db.com/exploits/46938unverifiedexploitdbwww.exploit-db.com/exploits/46976unverifiedgithubgithub.com/rogue-kdc/CVE-2019-0841★ 240githubgithub.com/0x00-0x00/CVE-2019-0841-BYPASS★ 58githubgithub.com/likekabin/CVE-2019-0841★ 2githubgithub.com/mappl3/CVE-2019-0841★ 0cve_referencepacketstormsecurity.com/files/152463/Microsoft-Windows-AppX-Deployment-Service-Privilege-Escalation.htmlunverifiedcve_referencepacketstormsecurity.com/files/153642/AppXSvc-Hard-Link-Privilege-Escalation.htmlunverifiedvulncheckvulncheck.com/xdb/e4ad3aaee5ddunverifiedcve_referencewww.exploit-db.com/exploits/46683/unverifiedcve_referencepacketstormsecurity.com/files/153114/Microsoft-Windows-AppX-Deployment-Service-Local-Privilege-Escalation.htmlunverifiedcve_referencepacketstormsecurity.com/files/153009/Internet-Explorer-JavaScript-Privilege-Escalation.htmlunverifiedcve_referencepacketstormsecurity.com/files/153215/Microsoft-Windows-AppX-Deployment-Service-Local-Privilege-Escalation.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — Microsoft Windows
In the same product, most dangerous first.
References
http://packetstormsecurity.com/files/152463/Microsoft-Windows-AppX-Deployment-Service-Privilege-Escalation.htmlhttp://packetstormsecurity.com/files/153009/Internet-Explorer-JavaScript-Privilege-Escalation.htmlhttp://packetstormsecurity.com/files/153114/Microsoft-Windows-AppX-Deployment-Service-Local-Privilege-Escalation.htmlhttp://packetstormsecurity.com/files/153215/Microsoft-Windows-AppX-Deployment-Service-Local-Privilege-Escalation.htmlhttp://packetstormsecurity.com/files/153642/AppXSvc-Hard-Link-Privilege-Escalation.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0841https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0841https://www.exploit-db.com/exploits/46683/https://www.zerodayinitiative.com/advisories/ZDI-19-360/