Rapid7’s 2026 Global Cybersecurity Summit is now available on-demand.Watch sessions.
Rapid7

vulnerability

Microsoft Windows: CVE-2020-16910: Windows Security Feature Bypass Vulnerability

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
Oct 13, 2020
Added
Oct 13, 2020
Modified
Sep 5, 2025

Description

A security feature bypass vulnerability exists when Microsoft Windows fails to handle file creation permissions, which could allow an attacker to create files in a protected Unified Extensible Firmware Interface (UEFI) location.To exploit this vulnerability, an attacker could run a specially crafted application to bypass Unified Extensible Firmware Interface (UEFI) variable security in Windows.The security update addresses the vulnerability by correcting security feature behavior to enforce permissions., aka 'Windows Security Feature Bypass Vulnerability'.

Solutions

microsoft-windows-windows_10-1507-kb4580327microsoft-windows-windows_10-1607-kb4580346microsoft-windows-windows_10-1709-kb4580328microsoft-windows-windows_10-1803-kb4580330microsoft-windows-windows_10-1809-kb4577668microsoft-windows-windows_10-1903-kb4577671microsoft-windows-windows_10-1909-kb4577671microsoft-windows-windows_10-2004-kb4579311microsoft-windows-windows_server_2016-1607-kb4580346microsoft-windows-windows_server_2019-1809-kb4577668msft-kb4577671-c42dc613-fb5b-4c45-925c-4f508584a635msft-kb4577671-ddbf4c81-6ca7-4986-999e-9275ef508017msft-kb4579311-e9f0550d-b150-4eeb-bf5e-1a08b117e7af
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.