← Back to browse · API

CVE-2019-1064

Severity
HIGH
CVSS
7.8
EPSS
0.06886
Risk score
58.61
CISA KEV
Yes
PoC
No
Published
2022-03-15
Modified
2022-03-15
First seen
2026-08-07
Aliases
EUVD-2019-9646, GHSA-7Q5J-W2G3-7F8V
Products
Microsoft:Windows, Microsoft:Windows 10 Version 1607 10.0.14393.0 <publication, Microsoft:Windows 10 Version 1703 10.0.0 <publication, Microsoft:Windows 10 Version 1709 10.0.0 <publication, Microsoft:Windows 10 Version 1709 for 32-bit Systems 10.0.0 <publication, Microsoft:Windows 10 Version 1803 10.0.0 <publication, Microsoft:Windows 10 Version 1809 10.0.0 <publication, Microsoft:Windows 10 Version 1809 10.0.17763.0 <publication, Microsoft:Windows 10 Version 1903 for 32-bit Systems 10.0.0 <publication, Microsoft:Windows 10 Version 1903 for ARM64-based Systems 10.0.0 <publication, Microsoft:Windows 10 Version 1903 for x64-based Systems 10.0.0 <publication, Microsoft:Windows Server 2016 (Server Core installation) 10.0.14393.0 <publication, Microsoft:Windows Server 2016 10.0.14393.0 <publication, Microsoft:Windows Server 2019 (Server Core installation) 10.0.17763.0 <publication, Microsoft:Windows Server 2019 10.0.17763.0 <publication, Microsoft:Windows Server, version 1803 (Server Core Installation) 10.0.0 <publication, Microsoft:Windows Server, version 1903 (Server Core installation) 10.0.0 <publication
Sources
euvd EUVD-2019-9646
cisa.gov CVE-2019-1064

Description

A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

References