CVE-2020-1292Improper Privilege Management in Microsoft Windows

Severity
7.8HIGHNVD
EPSS
12.1%
top 6.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 9
Latest updateMay 24

Description

An elevation of privilege vulnerability exists in OpenSSH for Windows when it does not properly restrict access to configuration settings, aka 'OpenSSH for Windows Elevation of Privilege Vulnerability'.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages13 packages

CVEListV5microsoft/windows6 versions+5
NVDmicrosoft/windows4 versions+3
NVDmicrosoft/windows_105 versions+4
CVEListV5microsoft/windows_server2019, 2019 (Core installation), version 1803 (Core Installation)+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-3gcv-cwcr-w49h: An elevation of privilege vulnerability exists in OpenSSH for Windows when it does not properly restrict access to configuration settings, aka 'OpenSS2022-05-24
CVEList
CVE-2020-1292: An elevation of privilege vulnerability exists in OpenSSH for Windows when it does not properly restrict access to configuration settings, aka 'OpenSS2020-06-09

📋Vendor Advisories

1
Microsoft
OpenSSH for Windows Elevation of Privilege Vulnerability2020-06-09
CVE-2020-1292 — Improper Privilege Management | cvebase