CVE-2020-16908 HIGH

CVE-2020-16908: Windows Setup Elevation of Privilege Vulnerability

Vendor Microsoft
Product Windows 10 Version 1803
Published October 16, 2020
Last update November 15, 2024

CVSS base score

7.8/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C

What the vulnerability does

01Description

<p>An elevation of privilege vulnerability exists in Windows Setup in the way it handles directories.</p> <p>A locally authenticated attacker could run arbitrary code with elevated system privileges. After successfully exploiting the vulnerability, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</p> <p>The security update addresses the vulnerability by ensuring Windows Setup properly handles directories.</p>

Key dates

02Disclosure timeline

October 16, 2020 CVE published
November 15, 2024 Record updated