CVE-2019-0573 EXPLOIT
7.8
HIGH · CVSS 3.0 · EPSS 20.1% (pctl 97)
Patch early
A public exploit exists.
Description
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Service Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows Server 2019, Windows 10 Servers. This CVE ID is unique from CVE-2019-0571, CVE-2019-0572, CVE-2019-0574.
Scoring
| CVSS | 7.8 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 20.14% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-862 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-01-08 |
| Last modified | 2026-06-17 |
Affected (3)
| Vendor | Product |
|---|---|
| microsoft | windows 10 |
| microsoft | windows server 2016 |
| microsoft | windows server 2019 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Windows 10 - DSSVC DSOpenSharedFile Arbitrary File Delete Privilege Escalation | 2019-01-14 |
References
- http://www.securityfocus.com/bid/106430
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0573
- https://www.exploit-db.com/exploits/46158/
- http://www.securityfocus.com/bid/106430
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0573
- https://www.exploit-db.com/exploits/46158/
→ the Explorer · watch your stack · NVD