High severity7.8CISA KEVNVD Advisory· Published Apr 9, 2019· Updated Jun 17, 2026
CVE-2019-0841
CVE-2019-0841
Description
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- cpe:2.3:o:microsoft:windows_10_1703:*:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_10_1709:*:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_10_1803:*:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_server_2016:1803:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*
- Range: version 1709 (Core Installation)
Patches
Vulnerability mechanics
References
9- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0841nvdPatchVendor Advisory
- packetstormsecurity.com/files/153642/AppXSvc-Hard-Link-Privilege-Escalation.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.exploit-db.com/exploits/46683/nvdExploitThird Party AdvisoryVDB Entry
- packetstormsecurity.com/files/152463/Microsoft-Windows-AppX-Deployment-Service-Privilege-Escalation.htmlnvdThird Party AdvisoryVDB Entry
- packetstormsecurity.com/files/153009/Internet-Explorer-JavaScript-Privilege-Escalation.htmlnvdThird Party AdvisoryVDB Entry
- packetstormsecurity.com/files/153114/Microsoft-Windows-AppX-Deployment-Service-Local-Privilege-Escalation.htmlnvdThird Party AdvisoryVDB Entry
- packetstormsecurity.com/files/153215/Microsoft-Windows-AppX-Deployment-Service-Local-Privilege-Escalation.htmlnvdThird Party AdvisoryVDB Entry
- www.zerodayinitiative.com/advisories/ZDI-19-360/nvdThird Party AdvisoryVDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.