nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-16940 CVE-2020-16940
HIGH
Windows - User Profile Service Elevation of Privilege Vulnerability
Record summary
CVE-2020-16940 has a selected CVSS score of 7.8 (high).
Description
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles junction points, aka 'Windows - User Profile Service Elevation of Privilege Vulnerability'.
Description source: GitHub Advisory
Affected products and versions
Showing 12 of 29| Product | Source | Version range | Status |
|---|---|---|---|
Windows 10 Version 1507Browse Microsoft / Windows 10 Version 1507 | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 1607Browse Microsoft / Windows 10 Version 1607 | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 1709Browse Microsoft / Windows 10 Version 1709 | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 1709 for 32-bit SystemsBrowse Microsoft / Windows 10 Version 1709 for 32-bit Systems | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 1803Browse Microsoft / Windows 10 Version 1803 | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 1809Browse Microsoft / Windows 10 Version 1809 | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 1903 for 32-bit SystemsBrowse Microsoft / Windows 10 Version 1903 for 32-bit Systems | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 1903 for ARM64-based SystemsBrowse Microsoft / Windows 10 Version 1903 for ARM64-based Systems | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 1903 for x64-based SystemsBrowse Microsoft / Windows 10 Version 1903 for x64-based Systems | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 1909Browse Microsoft / Windows 10 Version 1909 | CVE List | 10.0.0 to < publication | affected |
Windows 10 Version 2004Browse Microsoft / Windows 10 Version 2004 | CVE List | 10.0.0 to < publication | affected |
Windows 7Browse Microsoft / Windows 7 | CVE List | 6.1.0 to < publication | affected |
References
3portal.msrc.microsoft.com
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16940 zerodayinitiative.com
https://www.zerodayinitiative.com/advisories/ZDI-20-1248