logo

Windows EoP via UPnP & Update Services (CVE-2019)

ID: 33a9011b-d2ef-52c4-9b2a-929a580c3d1f

STIX ID: report--33a9011b-d2ef-52c4-9b2a-929a580c3d1f

Feed Name: NCC Research

Threat Score
70/100

Date Published: 2026-05-13

Date Updated: 2026-07-31

...
...

This NCC Group blog post describes two Windows vulnerabilities — CVE-2019-1405, a logic flaw in the UPnP Device Host COM interface that lets a local user instantiate COM objects as LOCAL SERVICE, and CVE-2019-1322, a misconfiguration in the Update Orchestrator service that allows SERVICE-group members to reconfigure a SYSTEM service; chained together these issues permit local privilege escalation to NT AUTHORITY\SYSTEM on default Windows 10 (versions 1803–1903). Patches were released in October and November 2019 to address the service permissions and COM access checks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.