SB2020112601 - Privilege escalation in Microsoft Windows
Published: November 26, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security restrictions bypass (CVE-ID: N/A)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect permissions set for two registry keys for the RPC Endpoint Mapper and DNSCache services. A local user can modify keys a leverage behavior of other system services to load a malicious DLL and execute arbitrary code with SYSTEM privileges.
Affected registry keys are:
- HKLMSYSTEMCurrentControlSetServicesRpcEptMapper
- HKLMSYSTEMCurrentControlSetServicesDnscache
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.