← Back to SOC feed Coverage →

detect-cve-2019-0973-installerbypass-exploit

kql MEDIUM Azure-Sentinel
DeviceProcessEvents
backdoorevasionexploithuntingmicrosoftofficial
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Azure-Sentinel →
Retrieved: 2026-05-24T11:00:00Z · Confidence: medium

Hunt Hypothesis

Adversaries may bypass installer restrictions to execute malicious payloads by exploiting CVE-2019-0973, allowing unauthorized code execution on compromised systems. SOC teams should proactively hunt for this behavior in Azure Sentinel to identify and mitigate potential lateral movement and persistence tactics used by advanced threats.

KQL Query

//Find possible use of InstallerBypass (Windows Installer Service exploit)
DeviceProcessEvents 
| where FileName =~ "msiexec.exe"
| where ProcessCommandLine contains "/fa" 
and ProcessCommandLine contains ":\\windows\\installer"

Analytic Rule Definition

id: 9c721e08-0a1b-4baf-b3ea-262dc1831faa
name: detect-cve-2019-0973-installerbypass-exploit
description: |
  This query was originally published in the threat analytics report, May 2019 0-day disclosures.
  In May and June of 2019, a security researcher with the online alias, SandboxEscaper, discovered and published several elevation-of-privilege vulnerabilities on Github. The researcher included proofs-of-concept demonstrating how to exploit these vulnerabilities.
  Patches and more information about each vulnerability are available below:
  1. CVE-2019-0863 | Windows Error Reporting Elevation of Privilege Vulnerability
  2. CVE-2019-1069 | Task Scheduler Elevation of Privilege Vulnerability
  3. CVE-2019-1053 | Windows Shell Elevation of Privilege Vulnerability
  4. CVE-2019-1064 | Windows Elevation of Privilege Vulnerability
  5. CVE-2019-0973 | Windows Installer Elevation of Privilege Vulnerability
  6. CVE-2019-1129 | Windows Elevation of Privilege Vulnerability
  This query locates possible activity that exploits CVE-2019-0973 (also known as InstallerBypass), the fifth vulnerability listed above.
  Reference - https://threatpost.com/sandboxescaper-more-exploits-ie-zero-day/145010/
requiredDataConnectors:
- connectorId: MicrosoftThreatProtection
  dataTypes:
  - DeviceProcessEvents
tactics:
- Privilege escalation
query: |
  //Find possible use of InstallerBypass (Windows Installer Service exploit)
  DeviceProcessEvents 
  | where FileName =~ "msiexec.exe"
  | where ProcessCommandLine contains "/fa" 
  and ProcessCommandLine contains ":\\windows\\installer"

Required Data Sources

Sentinel TableNotes
DeviceProcessEventsEnsure this data connector is enabled

MITRE ATT&CK Context

References

False Positive Guidance

Original source: https://github.com/Azure/Azure-Sentinel/blob/main/Hunting Queries/Microsoft 365 Defender/Privilege escalation/detect-cve-2019-0973-installerbypass-exploit.yaml