vulnerability
Microsoft Windows: CVE-2020-1467: Windows Hard Link Elevation of Privilege Vulnerability
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:L/AC:L/Au:N/C:C/I:C/A:C) | Aug 11, 2020 | Aug 11, 2020 | Sep 5, 2025 |
Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
Aug 11, 2020
Added
Aug 11, 2020
Modified
Sep 5, 2025
Description
An elevation of privilege vulnerability exists when Windows improperly handles hard links, aka 'Windows Hard Link Elevation of Privilege Vulnerability'.
Solutions
microsoft-windows-windows_10-1607-kb4571694microsoft-windows-windows_10-1809-kb4565349microsoft-windows-windows_10-1903-kb4565351microsoft-windows-windows_10-1909-kb4565351microsoft-windows-windows_10-2004-kb4566782microsoft-windows-windows_server_2012-kb4571702microsoft-windows-windows_server_2012_r2-kb4571723microsoft-windows-windows_server_2016-1607-kb4571694microsoft-windows-windows_server_2019-1809-kb4565349msft-kb4565351-4274f60c-bfeb-463c-9754-001689926626msft-kb4565351-79b74e87-e7f9-446e-a595-b7e944725115msft-kb4566782-912b8b41-c59a-4078-bfbf-fb69a4d8c0b3msft-kb4571702-66ebf6de-cf5f-4e3b-b54e-0a8c65fcba83msft-kb4571702-78dbaac1-754f-4c65-b12c-aaa62f7cfa56msft-kb4571719-670a205f-d483-4e65-98e1-95c5064c1e0dmsft-kb4571719-8542fd33-cd7f-4517-9e18-bb7a9c124557msft-kb4571719-a54fc6b2-280a-4b9e-b542-7b0f7499a259msft-kb4571719-a8e134c1-b2bf-4b38-9bdf-300153658fc6msft-kb4571719-bd67c0b7-a0f6-4c60-8c6c-76ce8156a3famsft-kb4571723-8bf56eb8-928f-4370-9a10-9724b3c610d0msft-kb4571723-c0b15391-31e8-444f-a876-c2f0108bfcc1msft-kb4571746-5133216e-6816-4331-a23e-e61db8d6d5d7msft-kb4571746-b0673aa6-5546-4b34-8677-6d03e87847f9
References
- CVE-2020-1467
- https://attackerkb.com/topics/CVE-2020-1467
- https://support.microsoft.com/help/4565349
- https://support.microsoft.com/help/4565351
- https://support.microsoft.com/help/4566782
- https://support.microsoft.com/help/4571694
- https://support.microsoft.com/help/4571702
- https://support.microsoft.com/help/4571723
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.