CVE-2020-16909

4 documents4 sources
Severity
7.8HIGH
EPSS
0.4%
top 40.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16
Latest updateMay 24

Description

An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of privilege if an attacker can successfully exploit it. An attacker who successfully exploited the vulnerability could gain greater access to sensitive information and system functionality. To exploit the vulnerability, an attacker could run a specially crafted application. The security update addresses the vulnerability by correcting the w

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages18 packages

CVEListV5microsoft/windows_server_201610.0.0publication

Patches

🔴Vulnerability Details

2
GHSA
GHSA-h95r-vwhr-286m: An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elev2022-05-24
CVEList
Windows Error Reporting Elevation of Privilege Vulnerability2020-10-16

📋Vendor Advisories

1
Microsoft
Windows Error Reporting Elevation of Privilege Vulnerability2020-10-13
CVE-2020-16909 (HIGH CVSS 7.8) | An elevation of privilege vulnerabi | cvebase.io