First published: Tue Jun 09 2020(Updated: )
An elevation of privilege vulnerability exists in OpenSSH for Windows when it does not properly restrict access to configuration settings, aka 'OpenSSH for Windows Elevation of Privilege Vulnerability'.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 10 | =1803 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows 10 | =1903 | |
Microsoft Windows 10 | =1909 | |
Microsoft Windows 10 | =2004 | |
Microsoft Windows Server 2016 | =1803 | |
Microsoft Windows Server 2016 | =1903 | |
Microsoft Windows Server 2016 | =1909 | |
Microsoft Windows Server 2016 | =2004 | |
Microsoft Windows Server 2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1292 has a critical severity rating due to its potential for elevation of privilege.
To fix CVE-2020-1292, update OpenSSH for Windows to the latest version provided by Microsoft.
CVE-2020-1292 affects Microsoft Windows 10 versions 1803, 1809, 1903, 1909, 2004, and Windows Server versions 2016 and 2019.
CVE-2020-1292 is categorized as an elevation of privilege vulnerability.
No, CVE-2020-1292 specifically allows for local elevation of privilege, rather than remote code execution.