CVE-2020-0733 is an elevation of privilege vulnerability affecting the Microsoft Windows Malicious Software Removal Tool (MSRT), stemming from its improper handling of junctions. An attacker with local execution on a system could exploit this to gain elevated privileges, leading to high impact on confidentiality, integrity, and availability. With a CVSS score of 7.8 (HIGH), it requires local access and has low attack complexity. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.80CPE matchmatch criteria | cpe:2.3:a:microsoft:windows_malicious_software_removal_tool:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.