PT-2020-3822 · Microsoft · Connected User Experiences/Telemetry Service+1

Edwardzpeng

+2

·

Published

2020-08-11

·

Updated

2024-01-19

·

CVE-2020-1511

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Connected User Experiences and Telemetry Service (affected versions not specified)
Description: The issue is related to improper handling of file operations by the Connected User Experiences and Telemetry Service, which could allow an attacker to run processes in an elevated context. This can be exploited by running a specially crafted application on the victim system. The vulnerability is also associated with errors in handling memory objects, which can lead to privilege escalation.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2020-04184
CVE-2020-1511

Affected Products

Connected User Experiences/Telemetry Service
Windows