PT-2019-2602 · Microsoft · Windows

Published

2019-06-11

·

Updated

2020-08-24

·

CVE-2019-0986

CVSS v3.1

6.3

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows (affected versions not specified)
Description The issue is related to the improper handling of symlinks by the Windows User Profile Service (ProfSvc), which can lead to an elevation of privilege. This allows an attacker to potentially increase their privileges on the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-02482
CVE-2019-0986

Affected Products

Windows