CVE-2019-1129

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1130.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:microsoft:windows_10_1703:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1703:-:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_server_1803:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_1903:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*

History

03 Apr 2025, 21:01

Type Values Removed Values Added
CPE cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10:1903:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2016:1803:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2016:1903:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1703:-:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_server_1903:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_server_1803:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1703:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:x86:*
First Time Microsoft windows 10 1703
Microsoft windows 10 1709
Microsoft windows Server 1803
Microsoft windows 10 1903
Microsoft windows 10 1803
Microsoft windows 10 1809
Microsoft windows Server 1903

Information

Published : 2019-07-15 19:15

Updated : 2025-04-03 21:01


NVD link : CVE-2019-1129

Mitre link : CVE-2019-1129

CVE.ORG link : CVE-2019-1129


JSON object : View

Products Affected

microsoft

  • windows_server_1903
  • windows_10_1703
  • windows_10_1903
  • windows_10_1809
  • windows_10_1709
  • windows_server_1803
  • windows_10_1803
  • windows_server_2019
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')