Vulnerability record · CVE-2019-1405 · published 12 November 2019
CVE-2019-1405: Windows UPnP Service Improper COM Object Creation Privilege Escalation
Microsoft · Windows 10 1507
The Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, enabling a local attacker to elevate privileges. The flaw affects a broad set of Windows client and server versions and is listed in CISA's Known Exploited Vulnerabilities catalog, so it is a confirmed real-world target.
Description
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8, confirmed active exploitation in CISA KEV with ransomware use, and a wide affected product base make this a high-priority local privilege escalation flaw.
What it is
The Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, enabling a local attacker to elevate privileges. The flaw affects a broad set of Windows client and server versions and is listed in CISA's Known Exploited Vulnerabilities catalog, so it is a confirmed real-world target.
Impact
An attacker who can run code on a vulnerable host gains elevated privileges, up to SYSTEM, allowing full control of the machine. This enables credential theft, persistence, and lateral movement.
Attack surface
The CVSS vector is local (AV:L) with low privileges required (PR:L) and no user interaction (UI:N), so the attacker must already have a foothold on the host. The UPnP service is reachable locally and does not require network access or user action.
Exploitation
CISA KEV lists this as actively exploited with known ransomware campaign use, and EPSS shows a 30-day probability of 0.2995 (98th percentile). A public Packet Storm advisory exists, indicating exploit code is available.
What to do
- Apply the Microsoft security update for CVE-2019-1405 on all affected Windows versions immediately.
- Disable the UPnP Device Host and SSDP Discovery services where UPnP is not required.
- Restrict local logon and code execution to trusted users to reduce the initial foothold needed for exploitation.
- Monitor and block unnecessary COM object creation from low-privileged processes via application control policies.
- Verify patching across all listed Windows 7, 8.1, 10, and Server editions, including legacy systems.
Detection
- Monitor for unexpected child processes spawning from svchost.exe hosting the UPnP service with SYSTEM-level tokens.
- Audit Windows event logs for privilege escalation indicators such as new service creation or token manipulation by non-admin users.
- Hunt for known exploit artifacts or COM object instantiation patterns associated with the UPnP service from low-integrity processes.
- Track CISA KEV remediation status and alert on unpatched hosts running the UPnP service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-1405 to the Known Exploited Vulnerabilities catalog on 15 March 2022 as "Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 5 April 2022.
Affected products
15 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/155723/Microsoft-UPnP-Local-Privilege-Elevation.html | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1405 | PatchVendor Advisory |
| http://packetstormsecurity.com/files/155723/Microsoft-UPnP-Local-Privilege-Elevation.html | Third Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1405 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-1405 | US Government Resource |
Track CVE-2019-1405 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-1405), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.