Severity
6.7MEDIUM
EPSS
0.4%
top 38.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 14
Latest updateOct 26

Description

An elevation of privilege vulnerability exists when Group Policy Services Policy Processing improperly handle reparse points, aka 'Group Policy Services Policy Processing Elevation of Privilege Vulnerability'.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages13 packages

CVEListV5microsoft/windows18 versions+17
NVDmicrosoft/windows4 versions+3
NVDmicrosoft/windows_107 versions+6
CVEListV5microsoft/windows_server14 versions+13

Patches

🔴Vulnerability Details

16
GHSA
nope-validator Regular Expression Denial of Service vulnerability2024-10-26
GHSA
Knwl.js Regular Expression Denial of Service vulnerability2024-10-26
GHSA
validate.js Regular Expression Denial of Service vulnerability2024-10-26
GHSA
insane vulnerable to Regular Expression Denial of Service2024-10-26
GHSA
CommonRegexJS Regular Expression Denial of Service vulnerability2024-10-26

📋Vendor Advisories

6
Red Hat
insane: GHSL-2020-289: Regular Expression Denial of Service (ReDoS) in insane2024-10-26
Red Hat
Useragent: GHSL-2020-312: Regular Expression Denial of Service (ReDoS) in useragent2024-10-26
Red Hat
papaparse: RegExp used to detect numbers is vulnerable to ReDoS2023-01-11
Red Hat
python-jinja2: ReDoS vulnerability in the urlize filter2021-02-01
Microsoft
Group Policy Services Policy Processing Elevation of Privilege Vulnerability2020-07-14
CVE-2020-1333 (MEDIUM CVSS 6.7) | An elevation of privilege vulnerabi | cvebase.io