Record summary

CVE-2020-16940 has a selected CVSS score of 7.8 (high).

Description

An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles junction points, aka 'Windows - User Profile Service Elevation of Privilege Vulnerability'.

Description source: GitHub Advisory

Affected products and versions

Showing 12 of 29
ProductSourceVersion rangeStatus
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected

Windows 10 Version 1709 for 32-bit Systems

Browse Microsoft / Windows 10 Version 1709 for 32-bit Systems
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected

Windows 10 Version 1903 for 32-bit Systems

Browse Microsoft / Windows 10 Version 1903 for 32-bit Systems
CVE List10.0.0 to < publicationaffected

Windows 10 Version 1903 for ARM64-based Systems

Browse Microsoft / Windows 10 Version 1903 for ARM64-based Systems
CVE List10.0.0 to < publicationaffected

Windows 10 Version 1903 for x64-based Systems

Browse Microsoft / Windows 10 Version 1903 for x64-based Systems
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected
CVE List10.0.0 to < publicationaffected
CVE List6.1.0 to < publicationaffected

References

3