An elevation of privilege vulnerability in the Windows Universal Plug and Play (UPnP) service caused by improper allowance of COM object creation. Successful exploitation could enable an attacker to elevate privileges on the affected system.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit module (comahawk.rb) that exploits two chained local privilege escalation vulnerabilities (CVE-2019-1405 and CVE-2019-1322) on Windows 10 systems (builds 17133-18362, i.e., versions 1803 to 1809). The exploit works by first elevating privileges to NT AUTHORITY\LOCAL SERVICE using the UPnP Device Host Service, then further elevating to NT AUTHORITY\SYSTEM via the Update Orchestrator Service. The module uploads both an exploit binary and a customizable payload (typically a Meterpreter executable) to a writable directory (default: %TEMP%) on the target. It then executes the exploit, which in turn runs the payload as SYSTEM. The module requires an existing Meterpreter session and is only applicable to 64-bit Windows 10 systems within the specified build range. The structure is typical for a Metasploit local exploit module, with options for customizing file names, writable directory, and execution timing. No network endpoints are involved; all actions occur locally on the compromised host.
This repository contains a C++ project (COMahawk) that implements a local privilege escalation exploit targeting Microsoft Windows 10 (versions 1803 to 1903) via CVE-2019-1405 and CVE-2019-1322. The main code file, COMahawk.cpp, leverages COM interfaces and manipulates the Update Orchestrator Service (UsoSvc) to execute arbitrary commands as SYSTEM. By default, if no argument is provided, it creates a new local user 'Tomahawk' with password 'RibSt3ak69' and adds it to the administrators group. If a command is provided as an argument, it executes that command as SYSTEM. The exploit works by reconfiguring the UsoSvc service to run a custom command, then restoring it to its original state. The repository includes standard Visual Studio project files and a README with usage instructions and references. No network endpoints are present; the attack vector is local privilege escalation via Windows services and COM interfaces.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously encountered Microsoft memory-related vulnerability referenced for historical context only.
A previously identified similar privilege escalation vulnerability referenced for historical context only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.