CVE-2019-1174 is an elevation of privilege vulnerability in the PsmServiceExtHost.dll affecting Microsoft Windows 10, Server 2016, and Server 2019. An attacker could exploit this by running a specially crafted application, allowing them to execute code with elevated permissions. With a CVSS score of 7.0 (HIGH), this vulnerability requires local authentication and high attack complexity, but successful exploitation grants high confidentiality, integrity, and availability impact. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV entry, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1809CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:* | ||
1903CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1903:*:*:*:*:*:*:* | ||
1903CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:1903:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.