Elevation of Privilege Vulnerability in Microsoft Windows Defender
CVE-2020-1163
7.8HIGH
Key Information:
- Vendor
- Microsoft
- Status
- Vendor
- CVE Published:
- 9 June 2020
Summary
An elevation of privilege vulnerability exists in Microsoft Windows Defender that allows an attacker to delete arbitrary files on the system. To exploit this vulnerability, the attacker must gain access to the system itself. This could involve compromising user accounts or using social engineering techniques. Once logged in, the attacker can leverage this vulnerability to manipulate system files, causing potential data loss and impacting system integrity.
Affected Version(s)
Microsoft Forefront Endpoint Protection 2010
Microsoft Security Essentials = unspecified
Microsoft System Center Endpoint Protection
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved