CVE-2020-16920
HIGH 7.8EPSS 1.4%
<p>An elevation of privilege vulnerability exists when the Windows Application Compatibility Client Library improperly handles registry operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.</p><p>To exploit the vulnerability, an attacker would first need code execution on a victim system. An attacker could then run a specially crafted application.</p><p>The security update addresses the vulnerability by ensuring the Windows Application Compatibility Client Library properly handles registry operations.</p>
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 1.42% chance of exploitation in the next 30 days, 71th percentile
- Nuclei
- critical
- Published
- 2020-10-16
- Updated
- 2024-08-04