First published: Wed Aug 14 2019(Updated: )
An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted command that could exploit the vulnerability and delete protected files on an affected system once MpSigStub.exe ran again. The update addresses the vulnerability and blocks the arbitrary deletion.
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Defender | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 | =1607 | |
Microsoft Windows 10 | =1703 | |
Microsoft Windows 10 | =1709 | |
Microsoft Windows 7 | =sp1 | |
Microsoft Windows 8.1 | ||
Microsoft Windows RT 8.1 | ||
Microsoft Windows Server 2008 | =sp2 | |
Microsoft Windows Server 2008 | =r2-sp1 | |
Microsoft Windows Server 2008 | =r2-sp1 | |
Microsoft Windows Server 2012 | ||
Microsoft Windows Server 2012 | =r2 | |
Microsoft Windows Server 2016 | ||
Microsoft Forefront Endpoint Protection 2010 | ||
Microsoft Security Essentials | ||
Microsoft System Center Endpoint Protection | ||
Microsoft System Center Endpoint Protection | =2012 | |
Microsoft System Center Endpoint Protection | =2012-r2 | |
All of | ||
Any of | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 | =1607 | |
Microsoft Windows 10 | =1703 | |
Microsoft Windows 10 | =1709 | |
Microsoft Windows 7 | =sp1 | |
Microsoft Windows 8.1 | ||
Microsoft Windows RT 8.1 | ||
Microsoft Windows Server 2008 | =sp2 | |
Microsoft Windows Server 2008 | =r2-sp1 | |
Microsoft Windows Server 2008 | =r2-sp1 | |
Microsoft Windows Server 2012 | ||
Microsoft Windows Server 2012 | =r2 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Defender |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1161 is an elevation of privilege vulnerability in Microsoft Defender.
CVE-2019-1161 allows attackers to delete files in arbitrary locations using the MpSigStub.exe component of Windows Defender.
To exploit CVE-2019-1161, an attacker would first need to log on to the system.
CVE-2019-1161 is classified as a high severity vulnerability with a severity value of 7.1.
More information about CVE-2019-1161 can be found at the following reference: [CVE-2019-1161](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1161)