An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'.
History

Wed, 22 Oct 2025 00:30:00 +0000


Tue, 21 Oct 2025 20:30:00 +0000


Tue, 21 Oct 2025 19:30:00 +0000


Tue, 08 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 10 1709
Microsoft windows 10 1803
Microsoft windows 10 1809
Microsoft windows 10 1903
CPEs cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10:1903:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2016:1803:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2016:1903:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
Vendors & Products Microsoft windows 10
Microsoft windows 10 1709
Microsoft windows 10 1803
Microsoft windows 10 1809
Microsoft windows 10 1903

Fri, 07 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2022-05-23'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published: 2019-11-12T18:52:54.000Z

Updated: 2025-10-21T23:35:58.416Z

Reserved: 2018-11-26T00:00:00.000Z

Link: CVE-2019-1385

cve-icon Vulnrichment

Updated: 2024-08-04T18:13:30.512Z

cve-icon NVD

Status : Modified

Published: 2019-11-12T19:15:12.503

Modified: 2025-10-22T00:16:40.467

Link: CVE-2019-1385

cve-icon Redhat

No data.