LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-1405: Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 15, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Apr 5, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-1405 to its Known Exploited Vulnerabilities catalog on Mar 15, 2022, with a federal patch deadline of Apr 5, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation.

CVE-2019-1405 is a privilege-escalation vulnerability in the Microsoft Windows Universal Plug and Play (UPnP) service. It allows an attacker who already has a foothold on a system to gain higher privileges by abusing how that service handles COM object creation. Because privilege escalation is a common step after initial access, and because this issue has been tied to ransomware activity, it matters for any organization running Windows endpoints or servers where the UPnP service is present.

Defenders should treat it as a local elevation path that can turn a limited compromise into full system control. Confirm exact affected builds, patches, and any configuration notes directly against the Microsoft advisory; do not rely on secondary summaries alone.

How it works

The core issue is improper handling inside the Windows UPnP service that permits COM object creation in a way that elevates privileges. In practical terms, an attacker who can already run code at a lower integrity level abuses this service behavior to obtain higher privileges on the same host.

This is a classic local privilege-escalation pattern: the vulnerable service runs with elevated rights and fails to adequately restrict what objects or actions a less-privileged caller can trigger. Public detail on the precise COM interfaces or call sequences is limited here; treat any exploit write-ups as unconfirmed until validated against the vendor advisory and your own testing. The attacker still needs prior code execution or a way to interact with the service, so this vulnerability is typically chained after phishing, malware droppers, or other initial-access methods rather than used as a remote wormable entry point by itself.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows systems that include the Universal Plug and Play service. UPnP is commonly present on client and server SKUs, though it may be disabled or firewalled in hardened environments. Inventory is straightforward:

Telemetry signs of exploitation are those typical of local privilege escalation: unexpected process creation or token manipulation originating from UPnP-related processes, unusual COM activation patterns, or post-exploitation actions (credential dumping, lateral movement tools, ransomware staging) running as SYSTEM or high-integrity shortly after lower-privilege activity. Correlate EDR alerts for privilege-escalation techniques with hosts that still lack the relevant update. Absence of clear IoCs does not prove safety; patch status remains the primary indicator.

How to remediate

Apply the Microsoft security update that resolves CVE-2019-1405 as directed in the vendor advisory. CISA’s required action is to apply updates per vendor instructions; prioritize systems that are internet-facing, run untrusted code, or hold sensitive data.

Document the change and retain evidence of patch compliance for audit and incident-response readiness.

If you can't patch immediately

If immediate patching is blocked by change windows or compatibility testing, reduce risk with compensating controls while you schedule the update:

Track every exception and set a firm deadline to patch; known ransomware use raises the cost of delay.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities are frequently used after initial access to deploy ransomware or steal data. If you discover exploitation or have unpatched systems that showed suspicious elevation activity, follow your incident-response plan: isolate affected hosts, preserve forensic images, reset credentials that may have been accessed from the elevated context, and hunt for persistence and lateral movement. Organizations and individuals can also run a free exposure scan of their email addresses against known breach data sets to check whether credentials or personal information have already appeared in public breach corpora, then force password changes and enable multi-factor authentication where exposure is confirmed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
Added to CISA KEVMar 15, 2022
Federal patch deadlineApr 5, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities