← Vulnerability feed

Vulnerability record · CVE-2019-1184 · published 14 August 2019

CVE-2019-1184: Windows Core Shell COM Server Registrar Elevation of Privilege

Microsoft · Windows 10

Windows Core Shell COM Server Registrar improperly handles COM calls, leaving them unprotected. A logged-on attacker can run a crafted application to set certain items to run at a higher level and elevate permissions. The flaw matters because it allows local privilege escalation on affected Windows 10 and Windows Server systems.

6.7 CVSS 3.1 Medium EPSS 70% · top 0.6%
6.7CVSS 3.1 base score, v2 7.2
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An elevation of privilege vulnerability exists when Windows Core Shell COM Server Registrar improperly handles COM calls. An attacker who successfully exploited this vulnerability could potentially set certain items to run at a higher level and thereby elevate permissions. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. The update addresses this vulnerability by correcting unprotected COM calls.

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityAlthough CVSS is medium (6.7) and exploitation requires local access and user interaction, the high EPSS score and privilege escalation impact warrant prompt patching and monitoring.

What it is

Windows Core Shell COM Server Registrar improperly handles COM calls, leaving them unprotected. A logged-on attacker can run a crafted application to set certain items to run at a higher level and elevate permissions. The flaw matters because it allows local privilege escalation on affected Windows 10 and Windows Server systems.

Impact

An attacker who successfully exploits the flaw can elevate permissions and take control of the affected system. This can lead to full compromise of the host under the attacker's control.

Attack surface

The vulnerability is local (AV:L) and requires the attacker to first log on to the system. Exploitation also requires user interaction (UI:R) and low privileges (PR:L), meaning a local user must run a specially crafted application.

Exploitation

CISA KEV does not list this CVE, and no public exploit or ransomware usage is documented in the record. EPSS is high (0.70227, 99.348th percentile), indicating elevated predicted exploitation activity despite the lack of confirmed in-the-wild reports.

What to do

  • Apply the Microsoft security update referenced in the vendor advisory to correct unprotected COM calls.
  • Restrict interactive logon and local user rights to reduce the pool of accounts that can run crafted applications.
  • Enforce least privilege so standard users cannot execute untrusted binaries or scripts on affected hosts.
  • Monitor for and block execution of unknown or unsigned applications on Windows 10 and Windows Server 2016/2019 systems.

Detection

  • Monitor process creation for unusual or unsigned binaries launched by standard users that interact with COM components.
  • Audit Windows event logs for privilege escalation indicators, such as unexpected token elevation or process integrity level changes.
  • Track COM object registration and activation events for the Core Shell COM Server Registrar that deviate from baseline.
  • Correlate local logon events with subsequent suspicious process execution on affected Windows hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-1184 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-1350Windows DNS Server improper input validation remote code executionWindows DNS servers fail to properly handle certain requests, allowing remote code execution. The flaw is network-reachable, needs no authentication …KEVEPSS 97%analysed9.8CVE-2026-33824Double free in Windows IKE Extension enables remote code executionA double free flaw (CWE-415) exists in the Windows IKE Extension, reachable over the network by an unauthenticated attacker. Successful exploitation …KEVEPSS 1.6%analysed9.8CVE-2025-59287Microsoft WSUS deserialization flaw allows unauthenticated remote code executionWindows Server Update Service (WSUS) deserializes untrusted data, letting an unauthenticated network attacker run code on the server. The flaw is rat…KEVEPSS 100%analysed9.8CVE-2017-8543Windows Search memory handling flaw allows remote code executionWindows Search fails to properly handle objects in memory, allowing an unauthenticated remote attacker to execute code on affected Windows systems. T…KEVEPSS 74%analysed9.0CVE-2020-1040Microsoft Hyper-V RemoteFX vGPU input validation remote code executionHyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, allowing remote code …KEVEPSS 7.4%analysed8.8CVE-2026-21510Windows Shell protection mechanism failure allows security feature bypassWindows Shell contains a protection mechanism failure (CWE-693) that lets an unauthorized attacker bypass a security feature over a network. The flaw…KEVEPSS 24%analysed8.8CVE-2026-21513Microsoft MSHTML security feature bypass on WindowsCVE-2026-21513 is a protection mechanism failure (CWE-693) in the Microsoft MSHTML Framework that lets an unauthorized attacker bypass a security fea…KEVEPSS 16%analysed8.8CVE-2025-33073Windows SMB improper access control allows privilege elevationWindows SMB contains an improper access control flaw (CWE-284) that lets an authorized attacker elevate privileges over the network. Microsoft rates …KEVEPSS 83%analysed

Source: NIST National Vulnerability Database (record CVE-2019-1184), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.