Количество 5
Количество 5

CVE-2020-16940
<p>An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles junction points. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context.</p> <p>To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and delete files or folders of their choosing.</p> <p>The security update addresses the vulnerability by correcting how the Windows User Profile Service handles junction points.</p>

CVE-2020-16940
Windows - User Profile Service Elevation of Privilege Vulnerability
GHSA-386j-h4xj-j5ph
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles junction points, aka 'Windows - User Profile Service Elevation of Privilege Vulnerability'.

BDU:2020-05462
Уязвимость службы Windows User Profile Service (ProfSvc) операционных систем Windows, позволяющая нарушителю повысить свои привилегии

BDU:2020-04888
Уязвимость службы профилей пользователя Windows User Profile Service (ProfSvc) операционных систем Windows, позволяющая нарушителю повысить свои привилегии
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2020-16940 <p>An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles junction points. An attacker who successfully exploited this vulnerability could delete files and folders in an elevated context.</p> <p>To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and delete files or folders of their choosing.</p> <p>The security update addresses the vulnerability by correcting how the Windows User Profile Service handles junction points.</p> | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад |
![]() | CVE-2020-16940 Windows - User Profile Service Elevation of Privilege Vulnerability | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад |
GHSA-386j-h4xj-j5ph An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles junction points, aka 'Windows - User Profile Service Elevation of Privilege Vulnerability'. | CVSS3: 7.8 | 1% Низкий | около 3 лет назад | |
![]() | BDU:2020-05462 Уязвимость службы Windows User Profile Service (ProfSvc) операционных систем Windows, позволяющая нарушителю повысить свои привилегии | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад |
![]() | BDU:2020-04888 Уязвимость службы профилей пользователя Windows User Profile Service (ProfSvc) операционных систем Windows, позволяющая нарушителю повысить свои привилегии | CVSS3: 5.5 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу