Elevation of Privilege Vulnerability in Windows RPC Service by Microsoft
CVE-2019-1089

7.8HIGH

Key Information:

Vendor
Microsoft
Status
Vendor
CVE Published:
15 July 2019

Summary

An elevation of privilege vulnerability exists in the RPC service's Activation Kernel due to improper handling of RPC requests by rpcss.dll. This issue allows authenticated attackers to execute specially crafted applications, potentially gaining higher access rights within the affected Windows environment. Organizations should apply security updates promptly to mitigate the risks associated with this vulnerability.

Affected Version(s)

Multiple Multiple

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.