PT-2020-4149 · Microsoft · Windows Function Discovery Service+1

·

CVE-2020-1491

·

Published

2020-09-08

·

Updated

2023-12-31

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Windows Function Discovery Service (affected versions not specified)
Description: The issue is related to errors in privilege management within the Windows Function Discovery Service, allowing an attacker to potentially elevate their privileges. To exploit this, a locally authenticated attacker could run a specially crafted application, enabling them to execute code with elevated permissions. The vulnerability is addressed by ensuring the Windows Function Discovery Service properly handles objects in memory.
Recommendations: For the Windows Function Discovery Service, ensure the security update is applied to address the vulnerability by properly handling objects in memory. As a temporary workaround, consider restricting access to the Windows Function Discovery Service until the security update is applied.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04571
CVE-2020-1491

Affected Products

Windows
Windows Function Discovery Service