Description
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1130.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- microsoft / Windows10 Version 1703 for 32-bit Systems – 10 Version 1703 for 32-bit Systems
- microsoft / Windows10 Version 1703 for x64-based Systems – 10 Version 1703 for x64-based Systems
- microsoft / Windows10 Version 1709 for 32-bit Systems – 10 Version 1709 for 32-bit Systems
- microsoft / Windows10 Version 1709 for x64-based Systems – 10 Version 1709 for x64-based Systems
- microsoft / Windows10 Version 1803 for 32-bit Systems – 10 Version 1803 for 32-bit Systems
- microsoft / Windows10 Version 1803 for x64-based Systems – 10 Version 1803 for x64-based Systems
- microsoft / Windows10 Version 1803 for ARM64-based Systems – 10 Version 1803 for ARM64-based Systems
- microsoft / Windows10 Version 1809 for 32-bit Systems – 10 Version 1809 for 32-bit Systems
- microsoft / Windows10 Version 1809 for x64-based Systems – 10 Version 1809 for x64-based Systems
- microsoft / Windows10 Version 1809 for ARM64-based Systems – 10 Version 1809 for ARM64-based Systems
- microsoft / Windows10 Version 1709 for ARM64-based Systems – 10 Version 1709 for ARM64-based Systems
- microsoft / Windows 10 Version 1903 for 32-bit Systemsunspecified – unspecified
- microsoft / Windows 10 Version 1903 for ARM64-based Systemsunspecified – unspecified
- microsoft / Windows 10 Version 1903 for x64-based Systemsunspecified – unspecified
- microsoft / Windows Server2019 – 2019
- microsoft / Windows Server2019 (Core installation) – 2019 (Core installation)
- microsoft / Windows Serverversion 1803 (Core Installation) – version 1803 (Core Installation)
- microsoft / Windows Server, version 1903 (Server Core installation)unspecified – unspecified
References
Updated 9m ago · 8 sources