CVE-2019-1253
high-risk
Published 2019-09-11
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1215, CVE-2019-1278, CVE-2019-1303.
Do I need to act?
!
31.9% chance of exploitation in next 30 days
EPSS score — higher than 68% of all CVEs
!
CISA KEV: actively exploited in the wild
On the Known Exploited Vulnerabilities catalog — federal agencies must patch
!
1 public exploit available
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.8/10
High
LOCAL
/ LOW complexity
Affected Products (17)
Affected Vendors
References (5)
Third Party Advisory
http://packetstormsecurity.com/files/154488/AppXSvc-17763.1.amd64fre.rs5_release...
Third Party Advisory
http://packetstormsecurity.com/files/154488/AppXSvc-17763.1.amd64fre.rs5_release...
US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-...
66
/ 100
high-risk
Severity
24/34 · High
Exploitability
23/34 · High
Exposure
19/34 · Moderate