Skip to main content
HIGH

CVE-2019-1170

CVSS v3

7.9

HIGH

EPSS Score

2.2 %

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

An elevation of privilege vulnerability exists when reparse points are created by sandboxed processes allowing sandbox escape. An attacker who successfully exploited the vulnerability could use the sandbox escape to elevate privileges on an affected system. To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted application to take control over the affected system. The security update addresses the vulnerability by preventing sandboxed processes from creating reparse points targeting inaccessible files.

Technical details

Published
2019-08-14
Exploit-DB
EDB-47306

Frequently asked questions

What is CVE-2019-1170?

An elevation of privilege vulnerability exists when reparse points are created by sandboxed processes allowing sandbox escape. An attacker who successfully exploited the vulnerability could use the sandbox escape to elevate privileges on an affected system. To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted application to take control over the affected system. The security update addresses the vulnerability by preventing sandboxed processes from creating reparse points targeting inaccessible files.

Is CVE-2019-1170 actively exploited?

Active exploitation of CVE-2019-1170 has not been confirmed. The EPSS score is 2.2%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-1170?

CVE-2019-1170 has a CVSS v3 base score of 7.9 (HIGH severity).

Is CVE-2019-1170 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key