CVE-2020-16940

Severity
7.8HIGH
EPSS
0.3%
top 45.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16
Latest updateMay 24

Description

An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles junction points. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and delete files or folders of their choosing. The security update addresse

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages29 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-386j-h4xj-j5ph: An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles junction points, aka 'Windows - User2022-05-24
CVEList
Windows - User Profile Service Elevation of Privilege Vulnerability2020-10-16

📋Vendor Advisories

1
Microsoft
Windows - User Profile Service Elevation of Privilege Vulnerability2020-10-13
CVE-2020-16940 (HIGH CVSS 7.8) | An elevation of privilege vulnerabi | cvebase.io