An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0730, CVE-2019-0731, CVE-2019-0796, CVE-2019-0805, CVE-2019-0836.
https://www.zerodayinitiative.com/advisories/ZDI-19-360/
http://packetstormsecurity.com/files/153009/Internet-Explorer-JavaScript-Privilege-Escalation.html
https://www.tenable.com/blog/microsoft-s-july-2019-patch-tuesday-what-you-need-to-know
https://www.tenable.com/blog/tenable-roundup-for-microsofts-june-2019-patch-tuesday
https://github.com/HellofHackers/Exploits
https://github.com/whoismept/IronSharp
https://github.com/0x00-0x00/CVE-2019-0841-BYPASS
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0841
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0841
http://packetstormsecurity.com/files/153642/AppXSvc-Hard-Link-Privilege-Escalation.html
Published: 2019-04-09
Updated: 2026-06-17
Named Vulnerability: ByeBearKnown Exploited Vulnerability (KEV)
Base Score: 7.2
Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C
Severity: High
Base Score: 7.8
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity: High
EPSS: 0.414