Description
An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.
To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted command that could exploit the vulnerability and delete protected files on an affected system once MpSigStub.exe ran again.
The update addresses the vulnerability and blocks the arbitrary deletion.
To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted command that could exploit the vulnerability and delete protected files on an affected system once MpSigStub.exe ran again.
The update addresses the vulnerability and blocks the arbitrary deletion.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-9733 | An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted command that could exploit the vulnerability and delete protected files on an affected system once MpSigStub.exe ran again. The update addresses the vulnerability and blocks the arbitrary deletion. |
References
History
Fri, 20 Feb 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted command that could exploit the vulnerability and delete protected files on an affected system once MpSigStub.exe ran again. The update addresses the vulnerability and blocks the arbitrary deletion. | An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted command that could exploit the vulnerability and delete protected files on an affected system once MpSigStub.exe ran again. The update addresses the vulnerability and blocks the arbitrary deletion. |
Subscriptions
Microsoft
Subscribe
Forefront Endpoint Protection 2010
Subscribe
Security Essentials
Subscribe
System Center Endpoint Protection
Subscribe
Windows 10
Subscribe
Windows 7
Subscribe
Windows 8.1
Subscribe
Windows Defender
Subscribe
Windows Rt 8.1
Subscribe
Windows Server 2008
Subscribe
Windows Server 2012
Subscribe
Windows Server 2016
Subscribe
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2024-08-04T18:06:31.818Z
Reserved: 2018-11-26T00:00:00.000Z
Link: CVE-2019-1161
No data.
Status : Modified
Published: 2019-08-14T21:15:15.580
Modified: 2026-02-20T21:18:37.027
Link: CVE-2019-1161
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD