TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2020-16910

MEDIUM
6.2

Beschreibung

<p>A security feature bypass vulnerability exists when Microsoft Windows fails to handle file creation permissions, which could allow an attacker to create files in a protected Unified Extensible Firmware Interface (UEFI) location.</p> <p>To exploit this vulnerability, an attacker could run a specially crafted application to bypass Unified Extensible Firmware Interface (UEFI) variable security in Windows.</p> <p>The security update addresses the vulnerability by correcting security feature behavior to enforce permissions.</p>

CVE Details

CVSS v3.1 Bewertung6.2
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
AngriffsvektorLOCAL
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht10/16/2020
Zuletzt geandert2/23/2026
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

microsoft:windows_10microsoft:windows_server_2016microsoft:windows_server_2019

Schwachen (CWE)

CWE-281

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.