HackerFeeds
All CVEs

CVE-2019-1405

HIGH7.8
CISA KEV

Published 2019-11-12 · Updated 2026-08-12 · Source secure@microsoft.com

Description

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'.

CVSS vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CWE-269

CISA Known-Exploited Vulnerability

Product: MicrosoftWindows

Name: Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability

Date added: 2022-03-15 · Due: 2022-04-05

USED IN RANSOMWARE

Required action: Apply updates per vendor instructions.

View on NVD