CVE-2019-1385
Microsoft Windows, Microsoft Windows Server, Microsoft Windows 10 Version 1903 for 32-bit Systems
Published 12 Nov 2019 · updated 12 Aug 2026 · Analyzed
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 23 May 2022, with a remediation deadline of 13 Jun 2022 for US federal agencies. It has been used in ransomware campaigns.
Required action: Apply updates per vendor instructions.
Description
An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'.
References
- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1385 · Patch, Vendor Advisory
- www.zerodayinitiative.com/advisories/ZDI-19-979/ · Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-1385 · US Government Resource