CVE-2019-1321HighCVSS 5.8
Microsoft Windows CloudStore Elevation of Privilege Vulnerability
🔗 CVE IDs covered (1)
📋 Description
An elevation of privilege vulnerability exists when Windows CloudStore improperly handles file Discretionary Access Control List (DACL). An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. The security update addresses the vulnerability by correcting how Windows CloudStore handles DACLs.
🎯 Affected products18
- Windows 10 Version 1703 for 32-bit Systems
- Windows 10 Version 1703 for x64-based Systems
- Windows 10 Version 1709 for 32-bit Systems
- Windows 10 Version 1709 for ARM64-based Systems
- Windows 10 Version 1709 for x64-based Systems
- Windows 10 Version 1803 for 32-bit Systems
- Windows 10 Version 1803 for ARM64-based Systems
- Windows 10 Version 1803 for x64-based Systems
- Windows 10 Version 1809 for 32-bit Systems
- Windows 10 Version 1809 for ARM64-based Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 Version 1903 for 32-bit Systems
- Windows 10 Version 1903 for ARM64-based Systems
- Windows 10 Version 1903 for x64-based Systems
- Windows Server 2019
- Windows Server 2019 (Server Core installation)
- Windows Server, version 1803 (Server Core Installation)
- Windows Server, version 1903 (Server Core installation)
✅ Remediation
KB4520010 (Security Update) KB4520008 (Security Update) KB4519338 (Security Update) KB4520004 (Security Update) KB4517389 (Security Update)
🔗 References (10)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2019-1321
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4520010
- referencehttps://support.microsoft.com/help/4520010
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4520008
- referencehttps://support.microsoft.com/help/4520008
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4519338
- referencehttps://support.microsoft.com/help/4519338
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4520004
- referencehttps://support.microsoft.com/help/4520004
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4517389