Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-1385

Опубликовано: 12 нояб. 2019
Источник: nvd
CVSS3: 7.8
CVSS2: 6.1
EPSS Низкий

Описание

An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*

EPSS

Процентиль: 59%
0.00381
Низкий

7.8 High

CVSS3

6.1 Medium

CVSS2

Дефекты

CWE-59
CWE-59

Связанные уязвимости

CVSS3: 7.8
msrc
больше 5 лет назад

Windows AppX Deployment Extensions Elevation of Privilege Vulnerability

CVSS3: 7.8
github
около 3 лет назад

An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'.

CVSS3: 7.8
fstec
больше 5 лет назад

Уязвимость компонента Windows AppX Deployment Server операционных систем Windows, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 59%
0.00381
Низкий

7.8 High

CVSS3

6.1 Medium

CVSS2

Дефекты

CWE-59
CWE-59