CVE-2020-1170 describes an elevation of privilege vulnerability in Microsoft Windows Defender, allowing an authenticated attacker to perform arbitrary file deletion on the system. This vulnerability carries a high CVSS score of 7.8, indicating significant impact (confidentiality, integrity, and availability) with low attack complexity, requiring local access. While no public exploit code is available via Metasploit or ExploitDB, and it is not listed in CISA's KEV catalog, there has been some community discussion and media coverage, suggesting awareness of its potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:windows_defender:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:forefront_endpoint_protection_2010:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:security_essentials:-:*:*:*:*:*:*:* | ||
2012CPE matchmatch criteria | cpe:2.3:a:microsoft:system_center_endpoint_protection:2012:*:*:*:*:*:*:* | ||
2012CPE matchmatch criteria | cpe:2.3:a:microsoft:system_center_endpoint_protection:2012:r2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.