CVE-2020-1002
7.1HIGH
Key Information:
- Vendor
- Microsoft
- Status
- Vendor
- CVE Published:
- 15 April 2020
Summary
An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vulnerability'.
Affected Version(s)
Microsoft Forefront Endpoint Protection 2010
Microsoft Security Essentials = unspecified
Microsoft System Center Endpoint Protection
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved