CVE-2019-1385 - Microsoft Windows
AI Vulnerability ContextAn elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka '...
Overview
A source-backed snapshot of this vulnerability.
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'.
Vulnerability status
How serious this vulnerability is and whether it is known to be exploited.
- CVE ID
- CVE-2019-1385
- Vendor/project
- Microsoft
- Product
- Windows
- Vulnerability name
- Microsoft Windows AppX Deployment Extensions Privilege Escalation Vulnerability
- Date added
- 2022-05-23
- Due date
- 2022-06-13
- Known ransomware campaign use
- Known
- CVSS v3
- 7.8
Exploit context
What the vulnerability is about.
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'.
Source evidence
Original public records and references for this page.
Original source
Original source links
Open the public records and source datasets used for this page.
