Permissions, Privileges, and Access Controls in Microsoft Windows and Windows Server - CVE-2020-1509
Published: August 12, 2020
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions in the Local Security Authority Subsystem Service (LSASS). A remote authenticated attacker can send a specially crafted request and gain elevated privileges on the target system.
Affected software
Windows Server