CVE-2020-16905Improper Privilege Management in Microsoft Windows 10 Version 1507

Severity
7.8HIGHNVD
CNA6.8
EPSS
0.8%
top 25.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16
Latest updateMay 24

Description

An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of privilege if an attacker can successfully exploit it. An attacker who successfully exploited the vulnerability could gain greater access to sensitive information and system functionality. To exploit the vulnerability, an attacker could run a specially crafted application. The security update addresses the vulnerability by correcting the w

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages16 packages

CVEListV5microsoft/windows_server_201610.0.0publication

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mr59-8hjw-5m9c: An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elev2022-05-24
CVEList
Windows Error Reporting Elevation of Privilege Vulnerability2020-10-16

📋Vendor Advisories

1
Microsoft
Windows Error Reporting Elevation of Privilege Vulnerability2020-10-13
CVE-2020-16905 — Improper Privilege Management | cvebase