An elevation of privilege vulnerability exists in the Local Security Authority Subsystem Service (LSASS) when an authenticated attacker sends a specially crafted authentication request. A remote attacker who successfully exploited this vulnerability could cause an elevation of privilege on the target system's LSASS service.
The security update addresses the vulnerability by changing the way that LSASS handles specially crafted authentication requests.
References
Link | Resource |
---|---|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1509 | Patch Vendor Advisory |
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1509 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 05:10
Type | Values Removed | Values Added |
---|---|---|
References | () https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1509 - Patch, Vendor Advisory |
19 Jan 2024, 00:15
Type | Values Removed | Values Added |
---|---|---|
Summary | An elevation of privilege vulnerability exists in the Local Security Authority Subsystem Service (LSASS) when an authenticated attacker sends a specially crafted authentication request. A remote attacker who successfully exploited this vulnerability could cause an elevation of privilege on the target system's LSASS service. The security update addresses the vulnerability by changing the way that LSASS handles specially crafted authentication requests. |
04 Jan 2024, 02:15
Type | Values Removed | Values Added |
---|---|---|
Summary | <p>An elevation of privilege vulnerability exists in the Local Security Authority Subsystem Service (LSASS) when an authenticated attacker sends a specially crafted authentication request. A remote attacker who successfully exploited this vulnerability could cause an elevation of privilege on the target system's LSASS service.</p> <p>The security update addresses the vulnerability by changing the way that LSASS handles specially crafted authentication requests.</p> | |
CVSS |
v2 : v3 : |
v2 : 6.5
v3 : 7.8 |
Information
Published : 2020-08-17 19:15
Updated : 2024-11-21 05:10
NVD link : CVE-2020-1509
Mitre link : CVE-2020-1509
CVE.ORG link : CVE-2020-1509
JSON object : View
Products Affected
microsoft
- windows_8.1
- windows_10
- windows_7
- windows_server_2019
- windows_rt_8.1
- windows_server_2012
- windows_server_2008
- windows_server_2016
CWE