Elevation of Privilege Vulnerability in Microsoft Defender
CVE-2020-1461

7.1HIGH

Summary

An elevation of privilege vulnerability can be exploited through the MpSigStub.exe component of Microsoft Defender. This vulnerability allows an unauthorized attacker to delete files in arbitrary locations. To successfully exploit this weakness, the attacker would first need to gain access to the system. The risk posed by this vulnerability highlights the importance of managing user permissions and keeping software updated.

Affected Version(s)

Microsoft Forefront Endpoint Protection 2010

Microsoft Security Essentials = unspecified

Microsoft System Center Endpoint Protection

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.