CVE-2019-1420 is an elevation of privilege vulnerability in Windows, affecting versions including Windows 7, 8.1, 10, and Server 2016/2019, stemming from improper handling of file creation by dssvc.dll. This allows an attacker to overwrite or create files in secured locations. With a CVSS score of 7.8 (High), it has a low attack complexity and requires local user privileges, potentially leading to high confidentiality, integrity, and availability impacts. While no public exploit code is available in Metasploit or ExploitDB, and it is not listed in CISA KEV, there has been limited community discussion and media coverage, indicating it is not widely exploited in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
1709CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:* | ||
1803CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:* | ||
1809CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.