PT-2020-4312 · Microsoft · Windows

Nabeel Ahmed

+1

·

Published

2020-10-13

·

Updated

2023-12-31

·

CVE-2020-16939

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Windows (affected versions not specified)
Description: The issue is related to an elevation of privilege vulnerability that exists when Group Policy improperly checks access. This could allow an attacker to run processes in an elevated context. To exploit this, an attacker would first need to log on to the system and then run a specially crafted application to take control over the affected system. The vulnerability is also described as a buffer overflow issue in the Group Policy Services of the Windows operating system, which could allow an attacker to elevate their privileges.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Improper Privilege Management

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04809
CVE-2020-16939
ZDI-20-1254

Affected Products

Windows