PT-2020-4268 · Microsoft · Windows
Published
2020-10-13
·
Updated
2023-12-31
·
CVE-2020-16910
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Windows (affected versions not specified)
Description:
A security feature bypass issue exists due to Windows' failure to handle file creation permissions properly, potentially allowing an attacker to create files in a protected Unified Extensible Firmware Interface (UEFI) location. To exploit this, an attacker could run a specially crafted application to bypass UEFI variable security in Windows. The issue could allow an attacker to elevate their privileges.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Preservation of Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows