New Search

Windows Lockscreen Elevation of Privilege Vulnerability - CVE-2020-1279

oval:org.cisecurity:def:7764

An elevation of privilege vulnerability exists when Windows Lockscreen fails to properly load spotlight images from a secure location. An attacker who successfully exploited the vulnerability could execute commands with elevated permissions. An authenticated attacker could modify a registry value to exploit this vulnerability. The security update addresses the vulnerability by ensuring that the spotlight images are always loaded from a secure location.

Family:
windows
Status:
ACCEPTED
Platform(s):
  • Microsoft Windows Server 2016
  • Microsoft Windows 10
  • Microsoft Windows Server 2019
Class:
vulnerability
Reference(s):
  • CVE-2020-1279
  • MSRC-CVE-2020-1279
  • KB4561616
  • KB4561602
  • KB4561621
  • KB4561608
  • KB4560960
Product(s):