Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2020-16908

Опубликовано: 15 окт. 2020
Источник: msrc
CVSS3: 7.8
EPSS Низкий

Описание

Windows Setup Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in Windows Setup in the way it handles directories.

A locally authenticated attacker could run arbitrary code with elevated system privileges. After successfully exploiting the vulnerability, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

The security update addresses the vulnerability by ensuring Windows Setup properly handles directories.

FAQ

There are no security updates listed for the affected versions of Windows. Where does this vulnerability exist?

This vulnerability only exists in Windows 10 Setup, which runs temporarily any time a customer upgrades from a previous version of Windows 10 to a newer version (for example, from Windows 10 Version 1909 to Windows 10 Version 2004). A device is vulnerable only while upgrading to a newer version of Windows. At any other time, the device is not vulnerable.

How do I know if I'm protected from this vulnerability?

As of this date, all in-support Feature Update bundles have been refreshed with the patched Setup binaries, so this vulnerability no longer exists.

If you are using WSUS or MEM ConfigMgr or another third-party management tool, please sync the latest feature update bundles and approve those for deployment. If you are using Windows media, as applicable to your system, please download the latest refreshed media from VLSC or Visual Studio Subscriptions (formerly MSDN), or download the latest applicable Setup Dynamic Update (DU) package and patch your existing media.

You can download the latest Setup DU packages from the Microsoft Update Catalog website. Please follow the instructions in the following article to learn about how to apply a Setup DU package to your existing media. Update remaining media files.

Following is a list of the latest Setup DU packages:

Setup DU PackageApplies To
4582759Windows 10 Version 1803
4582760Windows 10 Version 1809
4579919Windows 10 Version 1903
4579919Windows 10 Version 1909
4579308Windows 10 Version 2004

Возможность эксплуатации

Publicly Disclosed

Yes

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 71%
0.00713
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
почти 5 лет назад

<p>An elevation of privilege vulnerability exists in Windows Setup in the way it handles directories.</p> <p>A locally authenticated attacker could run arbitrary code with elevated system privileges. After successfully exploiting the vulnerability, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</p> <p>The security update addresses the vulnerability by ensuring Windows Setup properly handles directories.</p>

CVSS3: 7.8
github
около 3 лет назад

An elevation of privilege vulnerability exists in Windows Setup in the way it handles directories.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows Setup Elevation of Privilege Vulnerability'.

CVSS3: 7.8
fstec
почти 5 лет назад

Уязвимость службы установки приложений Windows Setup операционной системы Windows, позволяющая нарушителю повысить свои привилегии и получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 71%
0.00713
Низкий

7.8 High

CVSS3