6.3
CVE-2019-0986
- EPSS 2.05%
- Veröffentlicht 12.06.2019 14:29:02
- Zuletzt bearbeitet 20.05.2025 18:15:33
- Erkennungen
Windows User Profile Service Elevation of Privilege Vulnerability
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and delete files or folders of their choosing. The security update addresses the vulnerability by correcting how the Windows User Profile Service handles symlinks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 10 Version -
Microsoft ≫ Windows 10 Version 1607
Microsoft ≫ Windows 10 Version 1703
Microsoft ≫ Windows 10 Version 1709
Microsoft ≫ Windows 10 Version 1803
Microsoft ≫ Windows 10 Version 1809
Microsoft ≫ Windows 10 Version 1903
Microsoft ≫ Windows 8.1 Version -
Microsoft ≫ Windows Rt 8.1 Version -
Microsoft ≫ Windows Server 2008 Version - Update sp2
Microsoft ≫ Windows Server 2008 Version r2 Update sp1 HwPlatform itanium
Microsoft ≫ Windows Server 2008 Version r2 Update sp1 HwPlatform x64
Microsoft ≫ Windows Server 2012 Version -
Microsoft ≫ Windows Server 2012 Version r2
Microsoft ≫ Windows Server 2016 Version -
Microsoft ≫ Windows Server 2016 Version 1803
Microsoft ≫ Windows Server 2016 Version 1903
Microsoft ≫ Windows Server 2019 Version -
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.05% | 0.787 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Microsoft | 6.3 | 1 | 5.2 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
|
| NIST | 3.6 | 3.9 | 4.9 |
AV:L/AC:L/Au:N/C:N/I:P/A:P
|
| NIST | 7.1 | 1.8 | 5.2 |
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
|
CWE-59 Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0986
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2019-0986