First published: Wed Sep 11 2019(Updated: )
An elevation of privilege vulnerability exists in Windows store installer where WindowsApps directory is vulnerable to symbolic link attack, aka 'Microsoft Windows Store Installer Elevation of Privilege Vulnerability'.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Windows 10 | ||
Windows 10 | =1607 | |
Windows 10 | =1703 | |
Windows 10 | =1709 | |
Windows 10 | =1803 | |
Windows 10 | =1809 | |
Windows 10 | =1903 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2016 | =1803 | |
Microsoft Windows Server 2016 | =1903 | |
Microsoft Windows Server 2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-1270 is considered high due to its potential for elevation of privilege.
To fix CVE-2019-1270, ensure that you apply the latest security updates provided by Microsoft.
CVE-2019-1270 affects various versions of Microsoft Windows 10 and Microsoft Windows Server 2016 and 2019.
CVE-2019-1270 allows an attacker to perform a symbolic link attack leading to elevation of privilege.
No effective mitigation for CVE-2019-1270 can be implemented without applying the appropriate security patch.