Vulnerability record · CVE-2019-1184 · published 14 August 2019
CVE-2019-1184: Windows Core Shell COM Server Registrar Elevation of Privilege
Microsoft · Windows 10
Windows Core Shell COM Server Registrar improperly handles COM calls, leaving them unprotected. A logged-on attacker can run a crafted application to set certain items to run at a higher level and elevate permissions. The flaw matters because it allows local privilege escalation on affected Windows 10 and Windows Server systems.
Description
An elevation of privilege vulnerability exists when Windows Core Shell COM Server Registrar improperly handles COM calls. An attacker who successfully exploited this vulnerability could potentially set certain items to run at a higher level and thereby elevate permissions. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. The update addresses this vulnerability by correcting unprotected COM calls.
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityAlthough CVSS is medium (6.7) and exploitation requires local access and user interaction, the high EPSS score and privilege escalation impact warrant prompt patching and monitoring.
What it is
Windows Core Shell COM Server Registrar improperly handles COM calls, leaving them unprotected. A logged-on attacker can run a crafted application to set certain items to run at a higher level and elevate permissions. The flaw matters because it allows local privilege escalation on affected Windows 10 and Windows Server systems.
Impact
An attacker who successfully exploits the flaw can elevate permissions and take control of the affected system. This can lead to full compromise of the host under the attacker's control.
Attack surface
The vulnerability is local (AV:L) and requires the attacker to first log on to the system. Exploitation also requires user interaction (UI:R) and low privileges (PR:L), meaning a local user must run a specially crafted application.
Exploitation
CISA KEV does not list this CVE, and no public exploit or ransomware usage is documented in the record. EPSS is high (0.70227, 99.348th percentile), indicating elevated predicted exploitation activity despite the lack of confirmed in-the-wild reports.
What to do
- Apply the Microsoft security update referenced in the vendor advisory to correct unprotected COM calls.
- Restrict interactive logon and local user rights to reduce the pool of accounts that can run crafted applications.
- Enforce least privilege so standard users cannot execute untrusted binaries or scripts on affected hosts.
- Monitor for and block execution of unknown or unsigned applications on Windows 10 and Windows Server 2016/2019 systems.
Detection
- Monitor process creation for unusual or unsigned binaries launched by standard users that interact with COM components.
- Audit Windows event logs for privilege escalation indicators, such as unexpected token elevation or process integrity level changes.
- Track COM object registration and activation events for the Core Shell COM Server Registrar that deviate from baseline.
- Correlate local logon events with subsequent suspicious process execution on affected Windows hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1184 | PatchVendor Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1184 | PatchVendor Advisory |
Track CVE-2019-1184 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-1184), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.