Netskope Threat Labs

FILE-EXECUTABLE Microsoft Windows data sharing service privilege escalation attempt

IPS-CFW

1 SID: 48768

Detects the exploitation of CVE-2019-0574, a privilege escalation in the Windows data sharing service. The rule matches the serialized structures that public exploits use to trick the service into running code with elevated privileges.