vendor:
AppXSvc Deployment Service
by:
Abdelhamid Naceri
7.5
CVSS
HIGH
Elevation of Privileges
269
CWE
Product Name: AppXSvc Deployment Service
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
2019
Elevation of Privileges in Microsoft AppXSvc Deployment Service
An elevation of privileges vulnerability exists in the Microsoft AppXSvc Deployment Service. The vulnerability occurs when the service cannot properly handle a folder junction, leading to arbitrary file deletion from a low integrity user.
Mitigation:
Apply the latest security updates from Microsoft to address this vulnerability.