CVE-2019-1179: Windows Elevation of Privilege Vulnerability
An elevation of privilege vulnerability exists in the way that the unistore.dll handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1173, CVE-2019-1174, CVE-2019-1175, CVE-2019-1177, CVE-2019-1178, CVE-2019-1180, CVE-2019-1184, CVE-2019-1186.
Other sources
An elevation of privilege vulnerability exists in the way that the unistore.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application. The security update addresses the vulnerability by ensuring the unistore.dll properly handles objects in memory.
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Systems running the listed Microsoft Windows 10, Windows Server 2016, or Windows Server 2019 software are exposed if they have not applied the available security update. Exploitation requires a locally authenticated attacker, so remote unauthenticated access alone is not sufficient.
What does an attacker need to do to exploit this issue?
An attacker must be able to authenticate locally and run a specially crafted application. Successful exploitation can allow code execution with elevated permissions.
What should teams do to remediate the issue?
Apply the available security update, which corrects how unistore.dll handles objects in memory.