CVE-2019-0841 is an elevation of privilege vulnerability in the Windows AppX Deployment Service (AppXSVC) due to improper handling of hard links. The flaw allowed a low-privileged user to create hard links to SYSTEM-owned files, resulting in arbitrary DACL writes to those files. This could be exploited to take control of high-integrity files, such as those owned by SYSTEM, and escalate privileges. A bypass for the original patch was discovered, leveraging Microsoft Edge's settings.dat file and hardlinks to overwrite permissions on protected files, and could be chained with other privilege escalation vectors such as DLL hijacking or DiagHub Collector service abuse.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository contains a single Metasploit module (Ruby file) that exploits CVE-2019-0841, a privilege escalation vulnerability in Windows 10 (prior to build 17763) due to improper hard link handling by the AppXSvc service. The exploit leverages the Diagnostics Hub Standard Collector Service (DiagHub) to load a DLL as SYSTEM, granting full privilege escalation. The module checks the Windows build version, uploads required executables and payloads, creates a hard link from a user-controlled file to a SYSTEM-owned file (license.rtf), and uses DiagHub to execute the payload as SYSTEM. The exploit is operational and provides SYSTEM-level code execution. The main fingerprintable endpoints are file paths used for the hard link and payload delivery. The repository is structured as a typical Metasploit module, with all logic contained in a single Ruby file.
This repository contains a C++ project implementing a local privilege escalation (LPE) exploit for Microsoft Windows 10, targeting CVE-2019-0841. The main exploit logic is in 'ACLtakeoverLPE/ACLtakeoverLPE.cpp', which manipulates file permissions by abusing the way Microsoft Edge handles its settings file. The exploit works by creating a hardlink from the Edge settings file to a target file (e.g., 'C:\Windows\win.ini'), then restarting Edge to trigger a reset, which can result in the attacker gaining full control over the target file's ACL. The project includes supporting utility code for Windows API interaction, privilege manipulation, and hardlink creation. The exploit is operational and requires local access to the target system. No network endpoints are involved; the attack vector is purely local. The repository is structured as a standard Visual Studio C++ project, with the main entry point in 'ACLtakeoverLPE.cpp' and several supporting header and source files for Windows internals and utility functions.
This repository contains a C++ implementation of a local privilege escalation exploit targeting CVE-2019-0841 on Microsoft Windows 10 (x32 and x64). The main exploit logic resides in 'ACLtakeoverLPE/ACLtakeoverLPE.cpp', which is the entry point for the console application. The exploit works by creating a hardlink to a file used by Microsoft Edge, manipulating Edge's process state, and leveraging a flaw in how Windows handles file permissions to take over the ACL of an arbitrary file specified by the attacker. The attacker is then granted full control over the target file, which can be any file on the system (e.g., C:\Windows\win.ini). The exploit requires local access and is not a remote exploit. The repository includes supporting C++ source and header files for utility functions, NT API imports, and base64 encoding/decoding. Build files for Visual Studio are present, as well as resource files and logs from previous builds. The exploit is operational and provides a working payload for privilege escalation, but it is not part of a larger exploitation framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.