All CVEs View on NVD
CVE-2019-1405
HIGH7.8
CISA KEV
Published 2019-11-12 · Updated 2026-08-12 · Source secure@microsoft.com
Description
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'.
CVSS vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-269
CISA Known-Exploited Vulnerability
Product: Microsoft — Windows
Name: Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability
Date added: 2022-03-15 · Due: 2022-04-05
USED IN RANSOMWARE
Required action: Apply updates per vendor instructions.
References
- http://packetstormsecurity.com/files/155723/Microsoft-UPnP-Local-Privilege-Elevation.html
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1405
- http://packetstormsecurity.com/files/155723/Microsoft-UPnP-Local-Privilege-Elevation.html
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1405
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-1405

