LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-1129: Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 15, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Apr 5, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-1129 to its Known Exploited Vulnerabilities catalog on Mar 15, 2022, with a federal patch deadline of Apr 5, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.

CVE-2019-1129 is a privilege escalation vulnerability in the Microsoft Windows AppX Deployment Service (AppXSVC). It arises when the service improperly handles hard links, allowing an attacker who already has some access on a system to run processes in an elevated context. CISA notes known ransomware use of this issue, so unpatched Windows hosts remain a practical risk for lateral movement and full system compromise once an initial foothold exists.

Defenders should treat this as a local elevation path on Windows systems that run AppXSVC. Confirm exact affected builds, patches, and any configuration caveats directly against the Microsoft vendor advisory before declaring systems clear.

How it works

The weakness is classified as CWE-59 (Improper Link Resolution Before File Access, often called link following). In this case, AppXSVC does not correctly handle hard links when performing file operations related to app package deployment.

An attacker who can already execute code or write files in a less-privileged context can abuse the improper hard-link handling so that the service, which runs with higher privileges, operates on attacker-chosen targets. Successful exploitation lets the attacker run processes in an elevated context. Public detail on exact exploit mechanics is limited; do not assume specific file paths or sequences beyond the CISA description of improper hard-link handling. Confirm technical specifics against the vendor advisory.

Am I affected? How to find it in your systems

AppXSVC is a standard Windows component involved in deploying and managing Microsoft Store / AppX packages. It is present on modern client and server Windows installations that support those package types. Inventory every Windows endpoint and server, including virtual desktops and jump hosts.

How to remediate

Patch first. Apply the updates Microsoft released for CVE-2019-1129 exactly as described in the vendor advisory and per CISA’s required action: apply updates per vendor instructions. Use your standard enterprise deployment channel (WSUS, Intune, SCCM, or approved offline media), then verify installation via build/update inventory.

If you can't patch immediately

Compensate until the vendor update can be installed. These measures reduce likelihood or impact but do not replace the patch.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities, including those with known ransomware use, are commonly chained after initial access to dump credentials, deploy ransomware, or exfiltrate data. If you have evidence of exploitation or have unpatched systems that were reachable by untrusted users, follow your incident-response process: isolate hosts, preserve volatile evidence, reset credentials that may have been exposed, and hunt for persistence and lateral movement.

You can also run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in prior breaches, then force password resets and enable stronger authentication where needed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-59
Added to CISA KEVMar 15, 2022
Federal patch deadlineApr 5, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities