Elevation of Privilege Vulnerability in Microsoft Defender
CVE-2020-1002

7.1HIGH

Summary

An elevation of privilege vulnerability in the Microsoft Defender's MpSigStub.exe could allow attackers to delete files from arbitrary locations on the system. This vulnerability requires that an attacker has already logged into the system, making it a significant risk for system integrity. Proper safeguards and patch management are crucial to mitigating the impact of such vulnerabilities.

Affected Version(s)

Microsoft Forefront Endpoint Protection 2010

Microsoft Security Essentials = unspecified

Microsoft System Center Endpoint Protection

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.