Vulnerability record · CVE-2019-1253 · published 11 September 2019
CVE-2019-1253: Windows AppX Deployment Server junction handling privilege escalation
Microsoft · Windows 10 1703
The Windows AppX Deployment Server mishandles junctions, allowing a local attacker who already has code execution to elevate privileges. It matters because the flaw is confirmed exploited in the wild and has been used in ransomware campaigns.
Description
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1215, CVE-2019-1278, CVE-2019-1303.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8, confirmed KEV listing with ransomware use, and a public exploit make this a high-priority local privilege escalation despite requiring an existing foothold.
What it is
The Windows AppX Deployment Server mishandles junctions, allowing a local attacker who already has code execution to elevate privileges. It matters because the flaw is confirmed exploited in the wild and has been used in ransomware campaigns.
Impact
An attacker gains full control of the affected system, with high impact to confidentiality, integrity and availability. This typically means SYSTEM-level privileges on a Windows host.
Attack surface
Reached locally: the CVSS vector is AV:L with PR:L and UI:N, so the attacker needs existing low-privileged execution on the target and no user interaction. It is not remotely reachable and requires no authentication beyond that local foothold.
Exploitation
CISA added it to KEV on 2022-03-15 with known ransomware campaign use, and EPSS shows a 30-day probability of 0.116 (95.8th percentile). A public Packet Storm advisory exists, so exploitation is confirmed and active.
What to do
- Apply the Microsoft security update referenced in the vendor advisory (portal.msrc.microsoft.com) to all affected Windows 10 and Windows Server builds.
- Prioritize patching internet-facing and high-value hosts, and treat unpatched endpoints as compromised-capable given KEV status.
- Restrict local interactive logon and execution rights to reduce the low-privileged foothold this exploit requires.
- Monitor for and block known ransomware tooling and post-exploitation behavior on unpatched systems.
Detection
- Alert on processes creating or following junctions in AppX-related paths, especially unusual parent processes spawning from user-writable directories.
- Hunt for privilege escalation from medium-integrity to SYSTEM integrity on hosts running affected Windows builds.
- Correlate local process creation events with known exploit artifacts from the public Packet Storm advisory.
- Track unpatched assets against the KEV due date and flag any that remain unpatched past 2022-04-05.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-1253 to the Known Exploited Vulnerabilities catalog on 15 March 2022 as "Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 5 April 2022.
Affected products
8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/154488/AppXSvc-17763.1.amd64fre.rs5_release.180914-1434-Privilege-Escalation.html | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1253 | PatchVendor Advisory |
| http://packetstormsecurity.com/files/154488/AppXSvc-17763.1.amd64fre.rs5_release.180914-1434-Privilege-Escalation.html | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1253 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-1253 | US Government Resource |
Track CVE-2019-1253 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-1253), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.