<p>A security feature bypass vulnerability exists when Microsoft Windows fails to handle file creation permissions, which could allow an attacker to create files in a protected Unified Extensible Firmware Interface (UEFI) location.</p> <p>To exploit this vulnerability, an attacker could run a specially crafted application to bypass Unified Extensible Firmware Interface (UEFI) variable security in Windows.</p> <p>The security update addresses the vulnerability by correcting security feature behavior to enforce permissions.</p>
CVSS Details
- CVSS 3.1 Base Score: 6.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Msft | microsoft-windows-windows_10-1507-kb4580327microsoft-windows-windows_10-1607-kb4580346microsoft-windows-windows_10-1709-kb4580328microsoft-windows-windows_10-1803-kb4580330microsoft-windows-windows_10-1809-kb4577668microsoft-windows-windows_10-1903-kb4577671microsoft-windows-windows_10-1909-kb4577671microsoft-windows-windows_10-2004-kb4579311microsoft-windows-windows_server_2016-1607-kb4580346microsoft-windows-windows_server_2019-1809-kb4577668msft-kb4577671-c42dc613-fb5b-4c45-925c-4f508584a635msft-kb4577671-ddbf4c81-6ca7-4986-999e-9275ef508017msft-kb4579311-e9f0550d-b150-4eeb-bf5e-1a08b117e7af | Oct 13, 2020 | Oct 13, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub