VYPR

Windows AppX Deployment Service

by Microsoft

CVEs (19)

  • CVE-2019-0841HigKEVApr 9, 2019
    risk 0.75cvss 7.8epss 0.41

    An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836.

  • CVE-2019-1130HigKEVJul 15, 2019
    risk 0.69cvss 7.8epss 0.02

    An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1129.

  • CVE-2019-1129HigKEVJul 15, 2019
    risk 0.69cvss 7.8epss 0.02

    An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1130.

  • CVE-2019-1064HigKEVJun 12, 2019
    risk 0.69cvss 7.8epss 0.07

    An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context. An attacker could then install programs; view,…

  • CVE-2023-35322HigJul 11, 2023
    risk 0.57cvss 8.8epss 0.01

    Windows Deployment Services Remote Code Execution Vulnerability

  • CVE-2019-1476HigDec 10, 2019
    risk 0.54cvss 7.8epss 0.05

    An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1483.

  • CVE-2026-42987HigJun 9, 2026
    risk 0.53cvss 8.1epss 0.01

    Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.

  • CVE-2025-48820HigJul 8, 2025
    risk 0.51cvss 7.8epss 0.00

    Improper link resolution before file access ('link following') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally.

  • CVE-2021-41347HigOct 13, 2021
    risk 0.51cvss 7.8epss 0.01

    Windows AppX Deployment Service Elevation of Privilege Vulnerability

  • CVE-2019-1483HigDec 10, 2019
    risk 0.51cvss 7.8epss 0.02

    An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID…

  • CVE-2019-1340HigOct 10, 2019
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists in Windows AppX Deployment Server that allows file creation in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Elevation of Privilege Vulnerability'.…

  • CVE-2019-0766HigApr 9, 2019
    risk 0.51cvss 7.8epss 0.01

    An elevation of privilege vulnerability exists in Windows AppX Deployment Server that allows file creation in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Elevation of Privilege Vulnerability'.

  • CVE-2023-36395HigNov 14, 2023
    risk 0.49cvss 7.5epss 0.02

    Windows Deployment Services Denial of Service Vulnerability

  • CVE-2023-36567HigOct 10, 2023
    risk 0.49cvss 7.5epss 0.02

    Windows Deployment Services Information Disclosure Vulnerability

  • CVE-2023-36707MedOct 10, 2023
    risk 0.42cvss 6.5epss 0.03

    Windows Deployment Services Denial of Service Vulnerability

  • CVE-2023-36706MedOct 10, 2023
    risk 0.42cvss 6.5epss 0.02

    Windows Deployment Services Information Disclosure Vulnerability

  • CVE-2023-35321MedJul 11, 2023
    risk 0.42cvss 6.5epss 0.02

    Windows Deployment Services Denial of Service Vulnerability

  • CVE-2021-28326MedApr 13, 2021
    risk 0.36cvss 5.5epss 0.01

    Windows AppX Deployment Server Denial of Service Vulnerability

  • CVE-2026-49803HigJul 14, 2026
    risk 0.00cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally.