VDB
CISA-2019-1405
CISA-2019-1405
PUBLISHED
CVSS 7.8 HIGH
Reported by microsoft · Published November 12, 2019
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'.
Risk Scores
CVSS 3.1
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows | 7 for 32-bit Systems Service Pack 1, 7 for x64-based Systems Service Pack 1, 8.1 for 32-bit systems |
| Microsoft | Windows Server | 2008 R2 for x64-based Systems Service Pack 1 (Core installation), 2008 R2 for Itanium-Based Systems Service Pack 1, 2008 R2 for x64-based Systems Service Pack 1 |
| Microsoft | Windows 10 Version 1903 for 32-bit Systems | unspecified |
| Microsoft | Windows 10 Version 1903 for x64-based Systems | unspecified |
| Microsoft | Windows 10 Version 1903 for ARM64-based Systems | unspecified |
| Microsoft | Windows Server, version 1903 (Server Core installation) | unspecified |
| Microsoft | Windows 10 Version 1903 for 32-bit Systems | *, * |
| Microsoft | Windows Server | 2008 for 32-bit Systems Service Pack 2 (Core installation), 2008 R2 for x64-based Systems Service Pack 1 (Core installation), 2008 R2 for Itanium-Based Systems Service Pack 1 |
| Microsoft | Windows Server, version 1903 (Server Core installation) | unspecified, * |
| Microsoft | Windows 10 Version 1903 for x64-based Systems | unspecified, unspecified |
| Microsoft | Windows | *, *, 7 for 32-bit Systems Service Pack 1 |
| Microsoft | Windows 10 Version 1903 for ARM64-based Systems | *, unspecified |
Timeline
- Nov 12, 2019 CVE Published
- Oct 21, 2025 CVE Updated
References
- x_refsource_MISC
- x_refsource_MISC
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-1405 url