KEVIntel
7.8
CVSS
High

CVE-2019-0841

PUBLISHED

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation...

Exploited in the wild Used in malware Low complexity No user interaction
Vendor
Microsoft
Product
Windows, Windows Server
Published
Apr 09, 2019
EPSS

Description

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836.

windows cisa malware ransomware metasploit microsoft

CVSS scores

CVSS v3.1 7.8 High

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0 7.2

AV:L/AC:L/Au:N/C:C/I:C/A:C

Exploitation status

Exploited in the wild

Recorded 2022-03-15 00:00:00 UTC · Source

Used in malware

Recorded 2022-03-15 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Mar 15, 2022

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

appxsvc_hard_link_privesc

metasploit · Created Unknown

Metasploit module for CVE-2019-0841

mappl3/CVE-2019-0841

github · Created 2022-04-09 05:19:25 UTC · 0 stars

0x00-0x00/CVE-2019-0841-BYPASS

github · Created 2019-06-11 20:05:26 UTC · 59 stars

A fully automatic CVE-2019-0841 bypass targeting all versions of Edge in Windows 10.

likekabin/CVE-2019-0841

github · Created 2019-04-10 14:58:22 UTC · 2 stars

rogue-kdc/CVE-2019-0841

github · Created 2019-04-05 12:53:52 UTC · 240 stars

PoC code for CVE-2019-0841 Privilege Escalation vulnerability

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Exploit Used in Malware

  • Added to KEVIntel

  • Detected by Metasploit