CVE Database
/

CVE-2019-1405

Back to search

CVE-2019-1405

Published: Nov 12, 2019

Modified: Oct 21, 2025

PUBLISHED

Description

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'.

VendorProductVersions

Microsoft

Windows

affected
7 for 32-bit Systems Service Pack 1
affected
7 for x64-based Systems Service Pack 1
affected
8.1 for 32-bit systems
affected
8.1 for x64-based systems
affected
RT 8.1

+13 more versions

Microsoft

Windows Server

affected
2008 R2 for x64-based Systems Service Pack 1 (Core installation)
affected
2008 R2 for Itanium-Based Systems Service Pack 1
affected
2008 R2 for x64-based Systems Service Pack 1
affected
2008 for 32-bit Systems Service Pack 2 (Core installation)
affected
2012

+12 more versions

Microsoft

Windows 10 Version 1903 for 32-bit Systems

affected
unspecified

Microsoft

Windows 10 Version 1903 for x64-based Systems

affected
unspecified

Microsoft

Windows 10 Version 1903 for ARM64-based Systems

affected
unspecified

Microsoft

Windows Server, version 1903 (Server Core installation)

affected
unspecified

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now