PT-2020-3724 · Microsoft · Windows Setup

Halov

·

Published

2020-08-11

·

Updated

2024-01-19

·

CVE-2020-1571

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Windows Setup versions 1803 through 2004
Description: An elevation of privilege issue exists in the way Windows Setup handles permissions, allowing a locally authenticated attacker to run arbitrary code with elevated system privileges. This could enable an attacker to install programs, view, change, or delete data, or create new accounts with full user rights. The security update addresses this issue by ensuring Windows Setup properly handles permissions.
Recommendations: For Windows Setup versions 1803 through 2004, the security update should be applied to ensure Windows Setup properly handles permissions. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04082
CVE-2020-1571

Affected Products

Windows Setup