CVE-2019-1289
Last modified
CVE-2019-1289 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. An elevation of privilege vulnerability exists when the Windows Update Delivery Optimization does not properly enforce file share permissions, aka 'Windows Update Delivery Optimization Elevation of Privilege Vulnerability'.. EPSS estimates a 0.68% chance of exploitation in the next 30 days.
Description
An elevation of privilege vulnerability exists when the Windows Update Delivery Optimization does not properly enforce file share permissions, aka 'Windows Update Delivery Optimization Elevation of Privilege Vulnerability'.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows 10 | All versions |
| Microsoft | Windows 10 | 1607 |
| Microsoft | Windows 10 | 1703 |
| Microsoft | Windows 10 | 1709 |
| Microsoft | Windows 10 | 1803 |
| Microsoft | Windows 10 | 1809 |
| Microsoft | Windows 10 | 1903 |
| Microsoft | Windows Server 2016 | All versions |
| Microsoft | Windows Server 2016 | 1803 |
| Microsoft | Windows Server 2016 | 1903 |
| Microsoft | Windows Server 2019 | All versions |
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1289Patch, Vendor Advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1289Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-1289?
How severe is CVE-2019-1289?
How do I fix CVE-2019-1289?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-12880BCN Quark Quarking Password Manager 3.1.84 suffers from a cl…
- CVE-2019-12881i915_gem_userptr_get_pages in drivers/gpu/drm/i915/i915_gem_…7.8
- CVE-2019-12882Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-12887KeyIdentity LinOTP before 2.10.5.3 has Incorrect Access Cont…
- CVE-2019-12888Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-12889An unauthenticated privilege escalation exists in SailPoint …
- CVE-2019-12890RedwoodHQ 2.5.5 does not require any authentication for data…
- CVE-2019-12893Alternate Pic View 2.600 has a User Mode Write AV starting a…
- CVE-2019-12894Alternate Pic View 2.600 has a Read Access Violation at the …
- CVE-2019-12895In Alternate Pic View 2.600, the Exception Handler Chain is …
- CVE-2019-12896Edraw Max 7.9.3 has Heap Corruption starting at ntdll!RtlpNt…
- CVE-2019-12897Edraw Max 7.9.3 has a Read Access Violation at the Instructi…
Are you affected by CVE-2019-1289?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
