#VU46513 Permissions, Privileges, and Access Controls in Windows and Windows Server - CVE-2020-0951
Published: September 8, 2020
Windows
Windows Server
Microsoft
Description
The vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists in Windows Defender Application Control (WDAC), which could allow an attacker to bypass WDAC enforcement. To exploit the vulnerability, an attacker need administrator access on a local machine where PowerShell is running. The attacker could then connect to a PowerShell session and send commands to execute arbitrary code.