---
id: CVE-2019-1385
title: >-
  An elevation of privilege vulnerability exists when the Windows AppX
  Deployment Extensions improperly performs privilege management, resulting in
  access to system files.To exploit this vulnerability, an authenticated
  attacker would need …
summary: >-
  An elevation of privilege vulnerability exists when the Windows AppX
  Deployment Extensions improperly performs privilege management, resulting in
  access to system files.To exploit this vulnerability, an authenticated
  attacker would need …
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-59
  - CWE-59
vendor: microsoft
product: windows_10_1709
affected:
  - windows_10_1709
  - windows_10_1803
  - windows_10_1809
  - windows_10_1903
  - windows_server_2016
  - windows_server_2019
published: '2019-11-12'
updated: '2026-08-12'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2019-1385'
references:
  - url: >-
      https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1385
    label: secure@microsoft.com
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-19-979/'
    label: secure@microsoft.com
  - url: >-
      https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1385
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.zerodayinitiative.com/advisories/ZDI-19-979/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-1385
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
epss: 0.03604
epssPercentile: 0.88951
kev: true
kevDateAdded: '2022-05-23'
kevDueDate: '2022-06-13'
kevRansomware: true
exploited: true
zeroDay: true
ingestedAt: '2026-08-12T05:52:07.252Z'
---

## Overview

An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'.

## Affected

- `windows_10_1709`
- `windows_10_1803`
- `windows_10_1809`
- `windows_10_1903`
- `windows_server_2016`
- `windows_server_2019`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
