Elevation of Privilege Vulnerability in Windows Malicious Software Removal Tool by Microsoft
CVE-2020-0733
7.8HIGH
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 11 February 2020
Summary
An elevation of privilege vulnerability exists in the Windows Malicious Software Removal Tool (MSRT) due to improper handling of junctions. Successful exploitation allows an attacker to execute arbitrary code with elevated privileges on a target system, posing a significant security risk. To exploit this vulnerability, an attacker must first gain execution on the victim's system, making initial access crucial to the attack vector. This highlights the importance of maintaining robust security measures to detect and prevent unauthorized executable code from running.
Affected Version(s)
Windows Malicious Software Removal Tool 32-bit = unspecified
Windows Malicious Software Removal Tool 64-bit = unspecified
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved