CVE-2019-1064 is an elevation of privilege vulnerability in the Windows AppX Deployment Service (AppXSVC) that affects Microsoft products, stemming from improper handling of hard links. With a CVSS score of 7.8 (HIGH), this vulnerability allows a local attacker to run processes in an elevated context, potentially leading to full system compromise, including installing programs, viewing, changing, or deleting data. The vulnerability is actively exploited, listed in CISA's KEV catalog, and has a high FAUCET Risk Score of 98/100, indicating significant real-world risk. While no public Metasploit or ExploitDB modules exist, it has garnered substantial community discussion and media coverage, highlighting its importance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x64:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x86:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1703:-:*:*:*:*:*:x64:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1703:-:*:*:*:*:*:x86:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:arm64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.