PT-2020-4024 · Microsoft · Onedrive For Windows

Afang5472

+3

·

Published

2020-09-08

·

Updated

2023-12-31

·

CVE-2020-16852

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions: OneDrive for Windows (affected versions not specified)
Description: The issue is related to the improper handling of symbolic links by the OneDrive for Windows Desktop application. This could allow an attacker to overwrite a targeted file with an elevated status by running a specially crafted application. The attacker would first need to log on to the system to exploit this issue.
Recommendations: To resolve the issue, apply the update that corrects where the OneDrive updater performs file writes while running with elevation. At the moment, there is no information about specific versions that contain a fix for this vulnerability, so ensure to apply the latest available update.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2020-04424
CVE-2020-16852

Affected Products

Onedrive For Windows