Windows AppX Deployment Service
by Microsoft
CVEs (19)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-0841 | Hig | 0.75 | 7.8 | 0.41 | KEV | Apr 9, 2019 | An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836. | |
| CVE-2019-1130 | Hig | 0.69 | 7.8 | 0.02 | KEV | Jul 15, 2019 | An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129. | |
| CVE-2019-1129 | Hig | 0.69 | 7.8 | 0.02 | KEV | Jul 15, 2019 | An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1130. | |
| CVE-2019-1064 | Hig | 0.69 | 7.8 | 0.07 | KEV | Jun 12, 2019 | An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install programs; view,… | |
| CVE-2023-35322 | Hig | 0.57 | 8.8 | 0.01 | Jul 11, 2023 | Windows Deployment Services Remote Code Execution Vulnerability | ||
| CVE-2019-1476 | Hig | 0.54 | 7.8 | 0.05 | Dec 10, 2019 | An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1483. | ||
| CVE-2026-42987 | Hig | 0.53 | 8.1 | 0.01 | Jun 9, 2026 | Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-48820 | Hig | 0.51 | 7.8 | 0.00 | Jul 8, 2025 | Improper link resolution before file access ('link following') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally. | ||
| CVE-2021-41347 | Hig | 0.51 | 7.8 | 0.01 | Oct 13, 2021 | Windows AppX Deployment Service Elevation of Privilege Vulnerability | ||
| CVE-2019-1483 | Hig | 0.51 | 7.8 | 0.02 | Dec 10, 2019 | An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID… | ||
| CVE-2019-1340 | Hig | 0.51 | 7.8 | 0.01 | Oct 10, 2019 | An elevation of privilege vulnerability exists in Windows AppX Deployment Server that allows file creation in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Elevation of Privilege Vulnerability'.… | ||
| CVE-2019-0766 | Hig | 0.51 | 7.8 | 0.01 | Apr 9, 2019 | An elevation of privilege vulnerability exists in Windows AppX Deployment Server that allows file creation in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. | ||
| CVE-2023-36395 | Hig | 0.49 | 7.5 | 0.02 | Nov 14, 2023 | Windows Deployment Services Denial of Service Vulnerability | ||
| CVE-2023-36567 | Hig | 0.49 | 7.5 | 0.02 | Oct 10, 2023 | Windows Deployment Services Information Disclosure Vulnerability | ||
| CVE-2023-36707 | Med | 0.42 | 6.5 | 0.03 | Oct 10, 2023 | Windows Deployment Services Denial of Service Vulnerability | ||
| CVE-2023-36706 | Med | 0.42 | 6.5 | 0.02 | Oct 10, 2023 | Windows Deployment Services Information Disclosure Vulnerability | ||
| CVE-2023-35321 | Med | 0.42 | 6.5 | 0.02 | Jul 11, 2023 | Windows Deployment Services Denial of Service Vulnerability | ||
| CVE-2021-28326 | Med | 0.36 | 5.5 | 0.01 | Apr 13, 2021 | Windows AppX Deployment Server Denial of Service Vulnerability | ||
| CVE-2026-49803 | Hig | 0.00 | 7.0 | 0.00 | Jul 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally. |
- risk 0.75cvss 7.8epss 0.41
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836.
- risk 0.69cvss 7.8epss 0.02
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129.
- risk 0.69cvss 7.8epss 0.02
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1130.
- risk 0.69cvss 7.8epss 0.07
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install programs; view,…
- risk 0.57cvss 8.8epss 0.01
Windows Deployment Services Remote Code Execution Vulnerability
- risk 0.54cvss 7.8epss 0.05
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1483.
- risk 0.53cvss 8.1epss 0.01
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
- risk 0.51cvss 7.8epss 0.00
Improper link resolution before file access ('link following') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.01
Windows AppX Deployment Service Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.02
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID…
- risk 0.51cvss 7.8epss 0.01
An elevation of privilege vulnerability exists in Windows AppX Deployment Server that allows file creation in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Elevation of Privilege Vulnerability'.…
- risk 0.51cvss 7.8epss 0.01
An elevation of privilege vulnerability exists in Windows AppX Deployment Server that allows file creation in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Elevation of Privilege Vulnerability'.
- risk 0.49cvss 7.5epss 0.02
Windows Deployment Services Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.02
Windows Deployment Services Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.03
Windows Deployment Services Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.02
Windows Deployment Services Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.02
Windows Deployment Services Denial of Service Vulnerability
- risk 0.36cvss 5.5epss 0.01
Windows AppX Deployment Server Denial of Service Vulnerability
- risk 0.00cvss 7.0epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally.