CVE-2020-1509

HIGH

Windows LSASS - Authenticated Elevation of Privilege via Crafted Authentication Request

Title source: llm
STIX 2.1

Description

An elevation of privilege vulnerability exists in the Local Security Authority Subsystem Service (LSASS) when an authenticated attacker sends a specially crafted authentication request. A remote attacker who successfully exploited this vulnerability could cause an elevation of privilege on the target system's LSASS service. The security update addresses the vulnerability by changing the way that LSASS handles specially crafted authentication requests.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0326
EPSS Percentile 87.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (20)
microsoft/windows_10
microsoft/windows_10 1607
microsoft/windows_10 1709
microsoft/windows_10 1803
microsoft/windows_10 1809
microsoft/windows_10 1903
microsoft/windows_10 1909
microsoft/windows_10 2004
microsoft/windows_7
microsoft/windows_8.1
... and 10 more
Published Aug 17, 2020
Tracked Since Feb 18, 2026