LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-1385: Microsoft Windows AppX Deployment Extensions Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 23, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jun 13, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-1385 to its Known Exploited Vulnerabilities catalog on May 23, 2022, with a federal patch deadline of Jun 13, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.

CVE-2019-1385 is a privilege escalation vulnerability in Microsoft Windows AppX Deployment Extensions. When those extensions mishandle privilege management, an attacker who already has a foothold on a system can gain improper access to system files. Privilege escalation of this kind is commonly used to move from a limited user context to higher rights, which matters because the flaw has been tied to known ransomware activity. Confirm exact affected builds and patch identifiers against the Microsoft advisory.

How it works

The weakness is classified as CWE-59 (Improper Link Resolution Before File Access, often called link following). In this case the AppX Deployment Extensions do not correctly manage privileges when resolving or accessing paths, which can allow an attacker to reach system files they should not be able to touch.

An attacker who can already run code as a standard user abuses the flawed privilege handling so that operations performed by the AppX deployment components effectively grant elevated access. The result is the ability to read or manipulate protected system files. Exact exploit mechanics, preconditions, and any required user interaction are not detailed here; treat the CISA description as the authoritative high-level summary and verify technical specifics in the vendor advisory.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows systems that include the AppX Deployment Extensions component. AppX is the packaging and deployment technology used for modern Windows applications, so the component is present on typical client and many server installations that support Store or packaged apps.

How to remediate

Apply the security updates Microsoft released for this CVE, following the vendor’s instructions exactly. That is the CISA-required action and the primary fix.

If you can't patch immediately

Until the vendor update can be applied, reduce risk with compensating controls focused on limiting the attacker’s ability to reach and abuse the AppX deployment path.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities are frequently used in ransomware and broader intrusion chains. If you have evidence of exploitation or unpatched systems that were reachable by untrusted users, treat the incident as a potential breach: isolate affected hosts, preserve logs, and follow your incident-response process. You can also run a free exposure scan of your email addresses against known breach data to see whether credentials or personal information have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-59
Added to CISA KEVMay 23, 2022
Federal patch deadlineJun 13, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities