CVE-2020-1461 is an elevation of privilege vulnerability in Microsoft Defender's MpSigStub.exe component, allowing an authenticated attacker to delete files in arbitrary locations. With a CVSS score of 7.1 (HIGH), exploitation requires local access and has high integrity and availability impacts. There is no evidence of active exploitation, public exploit code, or significant community discussion, though it was mentioned in a July 2020 Patch Tuesday article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:windows_defender:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:forefront_endpoint_protection_2010:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:security_essentials:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:system_center_endpoint_protection:-:*:*:*:*:*:*:* | ||
2012CPE matchmatch criteria | cpe:2.3:a:microsoft:system_center_endpoint_protection:2012:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.