First published: Tue Jun 09 2020(Updated: )
An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Defender Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1163.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Defender | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 | =1607 | |
Microsoft Windows 10 | =1709 | |
Microsoft Windows 10 | =1803 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows 10 | =1903 | |
Microsoft Windows 10 | =1909 | |
Microsoft Windows 7 | =sp1 | |
Microsoft Windows 8.1 | ||
Microsoft Windows RT 8.1 | ||
Microsoft Windows Server 2008 | =sp2 | |
Microsoft Windows Server 2008 | =r2-sp1 | |
Microsoft Windows Server 2008 | =r2-sp1 | |
Microsoft Windows Server 2012 | ||
Microsoft Windows Server 2012 | =r2 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2016 | =1803 | |
Microsoft Windows Server 2016 | =1903 | |
Microsoft Windows Server 2016 | =1909 | |
Microsoft Windows Server 2019 | ||
Microsoft Forefront Endpoint Protection 2010 | ||
Microsoft Security Essentials | ||
Microsoft System Center Endpoint Protection | =2012 | |
Microsoft System Center Endpoint Protection | =2012-r2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-1170 is high with a CVSS score of 7.8.
CVE-2020-1170 is an elevation of privilege vulnerability in Windows Defender that can lead to arbitrary file deletion on the system.
To exploit CVE-2020-1170, an attacker would first have to log on to the system.
No, Microsoft Windows 10 is not affected by CVE-2020-1170.
Apply the latest security updates provided by Microsoft to fix CVE-2020-1170.