CVE-2019-0841
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- November 26, 2018
- Published Date
- April 09, 2019
- Last Updated
- February 07, 2025
- Vendor
- Microsoft
- Product
- Windows, Windows Server
- Description
- An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836.
CVSS Scores
CVSS v3.1
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
SSVC Information
- Exploitation
- active
- Technical Impact
- total
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2022-03-15 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/appxsvc_hard_link_privesc.rb | 2025-04-29 11:01:40 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
appxsvc_hard_link_privesc
Type: metasploit • Created: Unknown
mappl3/CVE-2019-0841
Type: github • Created: 2022-04-09 05:19:25 UTC • Stars: 0
0x00-0x00/CVE-2019-0841-BYPASS
Type: github • Created: 2019-06-11 20:05:26 UTC • Stars: 59
likekabin/CVE-2019-0841
Type: github • Created: 2019-04-10 14:58:22 UTC • Stars: 2
rogue-kdc/CVE-2019-0841
Type: github • Created: 2019-04-05 12:53:52 UTC • Stars: 240