Skip to content

AppXSvc Arbitrary File Overwrite DoS

Notifications You must be signed in to change notification settings

sgabe/CVE-2019-1476

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

CVE-2019-1476

AppXSvc Arbitrary File Overwrite DoS

I have independently reported this vulnerability to MSRC as part of my research inspired by CVE-2019-0841 originally reported by Nabeel Ahmed. This vulnerability allows a regular user to overwrite arbitrary files. However, the attacker's capabilities are limited, due to the lack of control over the file's content, hence it's most likely usage is in various denial of service scenarios. See Arbitrary file overwrite in AppXSvc for more information.

Video PoC