PT-2020-1661 · Microsoft · Windows Malicious Software Removal Tool

Ma7H1As

+1

·

Published

2020-02-11

·

Updated

2021-07-21

·

CVE-2020-0733

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows Malicious Software Removal Tool (MSRT) (affected versions not specified)
Description An elevation of privilege issue exists due to the Windows Malicious Software Removal Tool (MSRT) improperly handling junctions. To exploit this, an attacker must first gain execution on the victim system. The vulnerability can be exploited by a specially crafted application, allowing an attacker to elevate their privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00894
CVE-2020-0733

Affected Products

Windows Malicious Software Removal Tool