NVD disclosure day

Published threat advisories for July 15, 2019

CVE advisoryKnown Exploit

CVE-2019-1132

Windows Win32k Privilege Escalation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Windows Win32k component allows for privilege escalation. This could enable an attacker with local access to gain unauthorized control over affected systems and data, posing a business risk. Organizations should identify and secure vulnerable Windows assets.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2019-1130

Windows Elevation Vulnerability in AppX Deployment Service

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A Windows AppX Deployment Service vulnerability allows privilege escalation through improper hard link handling. Affected organizations face potential unauthorized system access and control. The realistic business risk involves a local attacker gaining elevated privileges on compromised systems.A Windows AppX Deploymen

• CISA KEV

CVE advisoryKnown Exploit

CVE-2019-1129

Windows Elevation of Privilege Via AppX Deployment Service

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Windows AppX Deployment Service (AppXSVC) allows for privilege escalation through improper handling of hard links. This impacts organizations by potentially enabling unauthorized access to systems and sensitive data. This is a business risk as it has been observed in ransomware campaigns, necessi

• CISA KEV

CVE advisoryKnown Exploit

CVE-2019-0880

Microsoft Windows Privilege Escalation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A local privilege escalation vulnerability in Windows' splwow64.exe component allows attackers with system access to gain higher permissions. This impacts affected Windows systems, potentially leading to unauthorized data access or modifications. The realistic business risk involves compromised system integrity and una

• CISA KEV