Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2020-1313Improper Privilege Management in Microsoft Windows 10 Version 1903 FOR 32-bit Systems

Severity
7.8HIGHNVD
EPSS
81.6%
top 0.81%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJun 9
Latest updateMay 24

Description

An elevation of privilege vulnerability exists when the Windows Update Orchestrator Service improperly handles file operations, aka 'Windows Update Orchestrator Service Elevation of Privilege Vulnerability'.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages23 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-hcfw-mr8f-6c3h: An elevation of privilege vulnerability exists when the Windows Update Orchestrator Service improperly handles file operations, aka 'Windows Update Or2022-05-24

💥Exploits & PoCs

1
Metasploit
Windows Update Orchestrator unchecked ScheduleWork call

📋Vendor Advisories

1
Microsoft
Windows Update Orchestrator Service Elevation of Privilege Vulnerability2020-06-09

💬Community

1
Bugzilla
CVE-2020-14335 foreman: world-readable OMAPI secret through the ISC DHCP server2020-07-17