A security feature bypass vulnerability exists when Microsoft Windows fails to handle file creation permissions, which could allow an attacker to create files in a protected Unified Extensible Firmware Interface (UEFI) location.To exploit this vulnerability, an attacker could run a specially crafted application to bypass Unified Extensible Firmware Interface (UEFI) variable security in Windows.The security update addresses the vulnerability by correcting security feature behavior to enforce permissions., aka 'Windows Security Feature Bypass Vulnerability'.
References
Link | Resource |
---|---|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16910 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-10-16 16:15
Updated : 2020-10-21 09:01
NVD link : CVE-2020-16910
Mitre link : CVE-2020-16910
JSON object : View
CWE
CWE-281
Improper Preservation of Permissions
Products Affected
microsoft
- windows_server_2016
- windows_server_2019
- windows_10