CVE-2020-0800 is an elevation of privilege vulnerability in the Windows Work Folder Service that affects multiple versions of Windows, including Windows 10, 8.1, and various Windows Server editions. The vulnerability arises from improper handling of file operations within the service. It carries a high CVSS score of 7.8, indicating that a local attacker with low privileges could exploit it without user interaction to achieve high confidentiality, integrity, and availability impacts. While the vulnerability has a low EPSS score and is not listed in CISA's KEV catalog, there is no public exploit code available, nor is it known to be actively exploited. Community discussion and media coverage are minimal, with only one article mentioning it in the context of a broader patch Tuesday release.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
1709CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:* | ||
1803CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:* | ||
1809CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.