CVE-2020-0665Improper Privilege Management in Microsoft Windows

Severity
8.1HIGHNVD
EPSS
7.4%
top 8.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 11
Latest updateMay 24

Description

An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest, aka 'Active Directory Elevation of Privilege Vulnerability'.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages10 packages

CVEListV5microsoft/windows18 versions+17
NVDmicrosoft/windows4 versions+3
NVDmicrosoft/windows_106 versions+5
CVEListV5microsoft/windows_server17 versions+16

Patches

🔴Vulnerability Details

2
GHSA
GHSA-w5g8-rp5c-h35j: An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest2022-05-24
CVEList
CVE-2020-0665: An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest2020-02-11

📋Vendor Advisories

1
Microsoft
Active Directory Elevation of Privilege Vulnerability2020-02-11

🕵️Threat Intelligence

2
Talos
Microsoft Patch Tuesday — Feb. 2020: Vulnerability disclosures and Snort coverage2020-02-11
Talos
Microsoft Patch Tuesday — Feb. 2020: Vulnerability disclosures and Snort coverage2020-02-11
CVE-2020-0665 — Improper Privilege Management | cvebase