PT-2020-3685 · Microsoft · Windows Appx Deployment Extensions+1

Ihack4Falafel

·

Published

2020-08-11

·

Updated

2024-01-19

·

CVE-2020-1488

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows AppX Deployment Extensions (affected versions not specified)
Description The issue is related to improper privilege management in the Windows AppX Deployment Extensions, allowing an authenticated attacker to elevate privileges by running a specially crafted application. This could result in access to system files. The security update corrects how AppX Deployment Extensions manages privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2020-04033
CVE-2020-1488

Affected Products

Windows
Windows Appx Deployment Extensions