CVE-2019-1405CISA KEV
Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation.
- Product
- Windows
- Added to KEV
- 15 Mar 2022
- Federal remediation due
- 5 Apr 2022
- Known ransomware use
- Yes