CVE-2020-16910: Windows Security Feature Bypass Vulnerability
<p>A security feature bypass vulnerability exists when Microsoft Windows fails to handle file creation permissions, which could allow an attacker to create files in a protected Unified Extensible Firmware Interface (UEFI) location.</p> <p>To exploit this vulnerability, an attacker could run a specially crafted application to bypass Unified Extensible Firmware Interface (UEFI) variable security in Windows.</p> <p>The security update addresses the vulnerability by correcting security feature behavior to enforce permissions.</p>
Other sources
A security feature bypass vulnerability exists when Microsoft Windows fails to handle file creation permissions, which could allow an attacker to create files in a protected Unified Extensible Firmware Interface (UEFI) location.To exploit this vulnerability, an attacker could run a specially crafted application to bypass Unified Extensible Firmware Interface (UEFI) variable security in Windows.The security update addresses the vulnerability by correcting security feature behavior to enforce permissions., aka 'Windows Security Feature Bypass Vulnerability'.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-16910?
CVE-2020-16910 is classified as a security feature bypass vulnerability.
How do I fix CVE-2020-16910?
To fix CVE-2020-16910, ensure you apply the latest security updates provided by Microsoft.
What versions of Windows are affected by CVE-2020-16910?
CVE-2020-16910 affects multiple versions of Windows 10 and Windows Server 2016 and 2019.
Can CVE-2020-16910 allow remote file creation?
Yes, exploit of CVE-2020-16910 could permit an attacker to create files in protected UEFI locations.
Is CVE-2020-16910 known to be actively exploited?
There is no public report that CVE-2020-16910 is actively being exploited in the wild at this time.