CVE-2020-1590: fallo de gravedad media en Microsoft Windows 10 Version 1809
Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability
Publicada el · Actualizada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 6.6epss 0.8%
probabilidad de explotación
0.8%top 44% de las CVE
explotación observada
noninguna fuente lo reporta
<p>An elevation of privilege vulnerability exists when the Connected User Experiences and Telemetry Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges on the victim system.</p>
<p>To exploit the vulnerability, an attacker would first have to gain execution on the victim system, then run a specially crafted application.</p>
<p>The security update addresses the vulnerability by correcting how the Connected User Experiences and Telemetry Service handles file operations.</p>
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L/E:P/RL:O/RC:C
Productos afectados
Microsoft · Windows 10 Version 1809Microsoft · Windows 10 Version 1903 for 32-bit SystemsMicrosoft · Windows 10 Version 1903 for ARM64-based SystemsMicrosoft · Windows 10 Version 1903 for x64-based SystemsMicrosoft · Windows 10 Version 1909Microsoft · Windows 10 Version 2004Microsoft · Windows Server 2019Microsoft · Windows Server 2019 (Server Core installation)Microsoft · Windows Server, version 1903 (Server Core installation)Microsoft · Windows Server, version 1909 (Server Core installation)Microsoft · Windows Server version 2004CVEs relacionadas — Microsoft Windows 10 Version 1809
En el mismo producto, de las más peligrosas a las menos.
CVE-2020-0796CRITICALCVE-2020-0796EPSS 99.8%KEVCVE-2021-34527HIGHWindows Print Spooler Remote Code Execution VulnerabilityEPSS 99.8%KEVCVE-2024-21412HIGHInternet Shortcut Files Security Feature Bypass VulnerabilityEPSS 99.4%KEVCVE-2022-30190HIGHMicrosoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution VulnerabilityEPSS 99.2%KEVCVE-2023-36884HIGHWindows Search Remote Code Execution VulnerabilityEPSS 98.9%KEVCVE-2021-40444HIGHMicrosoft MSHTML Remote Code Execution VulnerabilityEPSS 97.5%KEV