CVE-2020-0936Improper Privilege Management in Microsoft Windows

Severity
7.1HIGHNVD
EPSS
0.4%
top 41.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 15
Latest updateMay 24

Description

An elevation of privilege vulnerability exists when a Windows scheduled task improperly handles file redirections, aka 'Windows Scheduled Task Elevation of Privilege Vulnerability'.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:HExploitability: 1.8 | Impact: 5.2

Affected Packages10 packages

CVEListV5microsoft/windows16 versions+15
NVDmicrosoft/windows4 versions+3
NVDmicrosoft/windows_106 versions+5
CVEListV5microsoft/windows_server9 versions+8

Patches

🔴Vulnerability Details

2
GHSA
GHSA-g32v-q2cq-rp9w: An elevation of privilege vulnerability exists when a Windows scheduled task improperly handles file redirections, aka 'Windows Scheduled Task Elevati2022-05-24
CVEList
CVE-2020-0936: An elevation of privilege vulnerability exists when a Windows scheduled task improperly handles file redirections, aka 'Windows Scheduled Task Elevati2020-04-15

📋Vendor Advisories

1
Microsoft
Windows Scheduled Task Elevation of Privilege Vulnerability2020-04-14
CVE-2020-0936 — Improper Privilege Management | cvebase