ZeroHour

CVE-2020-16910

CVSS 3.1
6.2 medium
EPSS
3%p86
Published
()
Modified
Description

A security feature bypass vulnerability exists when Microsoft Windows fails to handle file creation permissions, which could allow an attacker to create files in a protected Unified Extensible Firmware Interface (UEFI) location. To exploit this vulnerability, an attacker could run a specially crafted application to bypass Unified Extensible Firmware Interface (UEFI) variable security in Windows. The security update addresses the vulnerability by correcting security feature behavior to enforce permissions.

Vendors
microsoft
Products
windows 10, windows server 2016, windows server 2019
Weakness
CWE-281
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.