CVE-2019-1000 is an elevation of privilege vulnerability in Microsoft Azure Active Directory Connect build 1.3.20.0. An authenticated attacker can exploit this by executing specific PowerShell cmdlets to perform privileged actions on the Azure AD Connect server. This vulnerability has a CVSS score of 5.3 (MEDIUM), indicating a network-based attack with high impact to integrity, but requiring low privileges and high attack complexity. There is no evidence of active exploitation, public exploit code, or inclusion in CISA's KEV catalog, though it has received some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:azure_active_directory_connect:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.