VYPR
Medium severity5.5NVD Advisory· Published Sep 11, 2019· Updated Jun 17, 2026

CVE-2019-1270

CVE-2019-1270

Description

An elevation of privilege vulnerability exists in Windows store installer where WindowsApps directory is vulnerable to symbolic link attack, aka 'Microsoft Windows Store Installer Elevation of Privilege Vulnerability'.

Affected products

18
  • cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_10:1903:*:*:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_server_2016:1803:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_server_2016:1903:*:*:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*
  • Microsoft/Windowsllm-fuzzy2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 10 for 32-bit Systems
  • Microsoft/Windows 10 Version 1903 for 32-bit Systemsv5
    Range: unspecified
  • Microsoft/Windows 10 Version 1903 for ARM64-based Systemsv5
    Range: unspecified
  • Microsoft/Windows 10 Version 1903 for x64-based Systemsv5
    Range: unspecified
  • Range: 2016
  • Microsoft/Windows Server, version 1903 (Server Core installation)v5
    Range: unspecified

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.