CVE-2019-1322 is a privilege escalation vulnerability in Microsoft Windows caused by a service misconfiguration. Specifically, it allows users in the local SERVICE group to reconfigure a service running as SYSTEM. When chained with CVE-2019-1405 (a logic error in the Windows UPnP Service), an unprivileged local user can escalate privileges to SYSTEM on default Windows 10 and earlier installations where the UPnP Device Host service is enabled. The vulnerability is local-only and cannot be exploited remotely without additional compromise.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit module (comahawk.rb) that exploits two chained local privilege escalation vulnerabilities (CVE-2019-1405 and CVE-2019-1322) on Windows 10 systems (builds 17133-18362, i.e., versions 1803 to 1809). The exploit works by first elevating privileges to NT AUTHORITY\LOCAL SERVICE using the UPnP Device Host Service, then further elevating to NT AUTHORITY\SYSTEM via the Update Orchestrator Service. The module uploads both an exploit binary and a customizable payload (typically a Meterpreter executable) to a writable directory (default: %TEMP%) on the target. It then executes the exploit, which in turn runs the payload as SYSTEM. The module requires an existing Meterpreter session and is only applicable to 64-bit Windows 10 systems within the specified build range. The structure is typical for a Metasploit local exploit module, with options for customizing file names, writable directory, and execution timing. No network endpoints are involved; all actions occur locally on the compromised host.
This repository contains a C++ project (COMahawk) that implements a local privilege escalation exploit targeting Microsoft Windows 10 (versions 1803 to 1903) via CVE-2019-1405 and CVE-2019-1322. The main code file, COMahawk.cpp, leverages COM interfaces and manipulates the Update Orchestrator Service (UsoSvc) to execute arbitrary commands as SYSTEM. By default, if no argument is provided, it creates a new local user 'Tomahawk' with password 'RibSt3ak69' and adds it to the administrators group. If a command is provided as an argument, it executes that command as SYSTEM. The exploit works by reconfiguring the UsoSvc service to run a custom command, then restoring it to its original state. The repository includes standard Visual Studio project files and a README with usage instructions and references. No network endpoints are present; the attack vector is local privilege escalation via Windows services and COM interfaces.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.