CVE-2020-0863Insecure Operation on Windows Junction / Mount Point in Microsoft Windows 10 Version 1903 FOR 32-bit Systems

Severity
5.5MEDIUMNVD
EPSS
0.4%
top 39.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 12
Latest updateMay 24

Description

An information vulnerability exists when Windows Connected User Experiences and Telemetry Service improperly discloses file information, aka 'Connected User Experiences and Telemetry Service Information Disclosure Vulnerability'.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages16 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-r935-6qcx-c53r: An information vulnerability exists when Windows Connected User Experiences and Telemetry Service improperly discloses file information, aka 'Connecte2022-05-24

📋Vendor Advisories

1
Microsoft
Connected User Experiences and Telemetry Service Information Disclosure Vulnerability2020-03-10

🕵️Threat Intelligence

2
Talos
Microsoft Patch Tuesday — March 2020: Vulnerability disclosures and Snort coverage2020-03-10
Talos
Microsoft Patch Tuesday — March 2020: Vulnerability disclosures and Snort coverage2020-03-10

📐Framework References

1
CWE
Insecure Operation on Windows Junction / Mount Point
CVE-2020-0863 — Microsoft vulnerability | cvebase