PT-2020-4024 · Microsoft · Onedrive For Windows
Afang5472
+3
·
Published
2020-09-08
·
Updated
2023-12-31
·
CVE-2020-16852
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
OneDrive for Windows (affected versions not specified)
Description:
The issue is related to the improper handling of symbolic links by the OneDrive for Windows Desktop application. This could allow an attacker to overwrite a targeted file with an elevated status by running a specially crafted application. The attacker would first need to log on to the system to exploit this issue.
Recommendations:
To resolve the issue, apply the update that corrects where the OneDrive updater performs file writes while running with elevation.
At the moment, there is no information about specific versions that contain a fix for this vulnerability, so ensure to apply the latest available update.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Onedrive For Windows