CVE-2019-1405: Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'.
Other sources
A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation.
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1405?
CVE-2019-1405 has a CVSS score of 7.8, indicating a high severity level and potential for exploitation.
How do I fix CVE-2019-1405?
To resolve CVE-2019-1405, apply the Microsoft security updates released for affected Windows versions.
Which Windows versions are affected by CVE-2019-1405?
CVE-2019-1405 affects multiple versions of Microsoft Windows including Windows 7, 8.1, 10, and various Windows Server editions.
What type of vulnerability is CVE-2019-1405?
CVE-2019-1405 is classified as an elevation of privilege vulnerability related to the Windows UPnP service.
Can CVE-2019-1405 be exploited remotely?
CVE-2019-1405 requires local access to exploit, as the vulnerability is related to improper COM object creation within the Windows environment.