vulnerability
Microsoft Windows: CVE-2020-0785: Windows User Profile Service Elevation of Privilege Vulnerability
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 4 | (AV:L/AC:L/Au:N/C:N/I:P/A:P) | Mar 10, 2020 | Mar 10, 2020 | Sep 5, 2025 |
Severity
4
CVSS
(AV:L/AC:L/Au:N/C:N/I:P/A:P)
Published
Mar 10, 2020
Added
Mar 10, 2020
Modified
Sep 5, 2025
Description
An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'.
Solutions
microsoft-windows-windows_10-1507-kb4540693microsoft-windows-windows_10-1607-kb4540670microsoft-windows-windows_10-1709-kb4540681microsoft-windows-windows_10-1803-kb4540689microsoft-windows-windows_10-1809-kb4538461microsoft-windows-windows_10-1903-kb4540673microsoft-windows-windows_10-1909-kb4540673microsoft-windows-windows_server_2012-kb4540694microsoft-windows-windows_server_2012_r2-kb4541505microsoft-windows-windows_server_2016-1607-kb4540670microsoft-windows-windows_server_2019-1809-kb4538461msft-kb4540673-27a7325b-a765-4956-ab15-a19091b61221msft-kb4540673-c13c3539-3ef4-481b-a305-d44fe74d2165msft-kb4540694-24482d48-0407-4e23-b911-d5e04acb91e5msft-kb4540694-c214d214-86c0-44d2-a9fe-1078a963bff4msft-kb4541500-4246fbc4-1ade-426a-9467-c69bac322cecmsft-kb4541500-67cee5f9-77e2-42fa-a7da-e94d1634c7dcmsft-kb4541500-6dd3e0b6-c1cb-474e-918a-f3f78e4afaedmsft-kb4541500-8f93f69e-cc61-4099-b875-dde648ec083bmsft-kb4541500-a2d1fed7-33cf-4d26-a56b-bc3829d9ecd0msft-kb4541505-823cc33f-f5a7-46f1-b525-2d93e9833273msft-kb4541505-e9e0fe16-c0c8-4a45-8696-f1746572cf0c
References
- CVE-2020-0785
- https://attackerkb.com/topics/CVE-2020-0785
- CWE-269
- URL-https://support.microsoft.com/help/4538461
- URL-https://support.microsoft.com/help/4540670
- URL-https://support.microsoft.com/help/4540673
- URL-https://support.microsoft.com/help/4540681
- URL-https://support.microsoft.com/help/4540689
- URL-https://support.microsoft.com/help/4540693
- URL-https://support.microsoft.com/help/4540694
- URL-https://support.microsoft.com/help/4541505
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.