Vulnerability Intelligence Report
Microsoft Defender Elevation of Privilege Vulnerability
CVE-2019-1161
An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted command that could exploit the vulnerability and delete protected files on an affected system once MpSigStub.exe ran again. The update addresses the vulnerability and blocks the arbitrary deletion.
No Active Exploit Signals
CVSS Base Score
7.1
HIGH
EPSS Probability:0.90%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Microsoft | Microsoft Forefront Endpoint Protection 2010 | N/A (affected) |
| Microsoft | Microsoft System Center Endpoint Protection | N/A (affected) |
| Microsoft | Microsoft System Center 2012 R2 Endpoint Protection | N/A (affected) |
| Microsoft | Microsoft Security Essentials | N/A (affected) |
| Microsoft | Microsoft System Center 2012 Endpoint Protection | N/A (affected) |
| Microsoft | Windows Defender | N/A (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.896%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Microsoft Corporation · Vendor · USA |
| Reserved | 2018-11-26T00:00:00 |
| Published | 2019-08-14T20:55:03 |
| Patch Date | 2019-08-13 |
| Last Updated | 2024-08-04T18:06:31 |
Community Chatter & Buzz