Vulnerability Description
An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Defender Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1163.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows Defender | - |
| Microsoft | Windows 10 | - |
| Microsoft | Windows 7 | - |
| Microsoft | Windows 8.1 | - |
| Microsoft | Windows Rt 8.1 | - |
| Microsoft | Windows Server 2008 | - |
| Microsoft | Windows Server 2012 | - |
| Microsoft | Windows Server 2016 | - |
| Microsoft | Windows Server 2019 | - |
| Microsoft | Forefront Endpoint Protection 2010 | - |
| Microsoft | Security Essentials | - |
| Microsoft | System Center Endpoint Protection | 2012 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/160919/Cloud-Filter-Arbitrary-File-CreationExploitThird Party AdvisoryVDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1170PatchVendor Advisory
- http://packetstormsecurity.com/files/160919/Cloud-Filter-Arbitrary-File-CreationExploitThird Party AdvisoryVDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1170PatchVendor Advisory
FAQ
What is CVE-2020-1170?
CVE-2020-1170 is a vulnerability with a CVSS score of 7.8 (HIGH). An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an attacker would first have to log on to the system, ...
How severe is CVE-2020-1170?
CVE-2020-1170 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-1170?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Windows Defender, Microsoft Windows 10, Microsoft Windows 7, Microsoft Windows 8.1, Microsoft Windows Rt 8.1.