An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'.
History

Tue, 08 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 10 1709
Microsoft windows 10 1803
Microsoft windows 10 1809
Microsoft windows 10 1903
CPEs cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10:1903:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2016:1803:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2016:1903:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
Vendors & Products Microsoft windows 10
Microsoft windows 10 1709
Microsoft windows 10 1803
Microsoft windows 10 1809
Microsoft windows 10 1903

Fri, 07 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2022-05-23'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2025-02-07T16:18:11.792Z

Reserved: 2018-11-26T00:00:00.000Z

Link: CVE-2019-1385

cve-icon Vulnrichment

Updated: 2024-08-04T18:13:30.512Z

cve-icon NVD

Status : Analyzed

Published: 2019-11-12T19:15:12.503

Modified: 2025-04-08T15:43:31.330

Link: CVE-2019-1385

cve-icon Redhat

No data.