An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges.
To exploit the vulnerability, an attacker could run a specially crafted application that could exploit the vulnerability. This vulnerability by itself does not allow arbitrary code to be run. However, this vulnerability could be used in conjunction with one or more vulnerabilities (e.g. a remote code execution vulnerability and another elevation of privilege) that could take advantage of the elevated privileges when running.
The update addresses the vulnerability by correcting how the Windows Audio Service handles processes these requests.
References
Link | Resource |
---|---|
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2019-1007 | |
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1007 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
20 May 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Summary | (en) An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that could exploit the vulnerability. This vulnerability by itself does not allow arbitrary code to be run. However, this vulnerability could be used in conjunction with one or more vulnerabilities (e.g. a remote code execution vulnerability and another elevation of privilege) that could take advantage of the elevated privileges when running. The update addresses the vulnerability by correcting how the Windows Audio Service handles processes these requests. |
21 Nov 2024, 04:35
Type | Values Removed | Values Added |
---|---|---|
References | () https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1007 - Patch, Vendor Advisory |
Information
Published : 2019-06-12 14:29
Updated : 2025-05-20 18:15
NVD link : CVE-2019-1007
Mitre link : CVE-2019-1007
CVE.ORG link : CVE-2019-1007
JSON object : View
Products Affected
microsoft
- windows_10
- windows_server_2019
- windows_server_2016
CWE
CWE-269
Improper Privilege Management