An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.
To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted command that could exploit the vulnerability and delete protected files on an affected system once MpSigStub.exe ran again.
The update addresses the vulnerability and blocks the arbitrary deletion.
To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted command that could exploit the vulnerability and delete protected files on an affected system once MpSigStub.exe ran again.
The update addresses the vulnerability and blocks the arbitrary deletion.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Microsoft
Subscribe
|
Forefront Endpoint Protection 2010
Subscribe
Security Essentials
Subscribe
System Center Endpoint Protection
Subscribe
Windows 10
Subscribe
Windows 7
Subscribe
Windows 8.1
Subscribe
Windows Defender
Subscribe
Windows Rt 8.1
Subscribe
Windows Server 2008
Subscribe
Windows Server 2012
Subscribe
Windows Server 2016
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-9733 | An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted command that could exploit the vulnerability and delete protected files on an affected system once MpSigStub.exe ran again. The update addresses the vulnerability and blocks the arbitrary deletion. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2024-08-04T18:06:31.818Z
Reserved: 2018-11-26T00:00:00
Link: CVE-2019-1161
No data.
Status : Modified
Published: 2019-08-14T21:15:15.580
Modified: 2024-11-21T04:36:08.930
Link: CVE-2019-1161
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD