SB2020090874 - Privilege escalation in Windows Defender



SB2020090874 - Privilege escalation in Windows Defender

Published: September 8, 2020

Security Bulletin ID SB2020090874
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2020-0951)

The vulnerability allows a local user to bypass implemented security restrictions.

The vulnerability exists in Windows Defender Application Control (WDAC), which could allow an attacker to bypass WDAC enforcement. To exploit the vulnerability, an attacker need administrator access on a local machine where PowerShell is running. The attacker could then connect to a PowerShell session and send commands to execute arbitrary code.


Remediation

Install update from vendor's website.