CVE-2020-1011 is an elevation of privilege vulnerability in the Windows System Assessment Tool (WinSAT) that affects various versions of Windows 10, 7, 8.1, RT 8.1, and Windows Server 2016/2019. This flaw stems from WinSAT's improper handling of file operations, allowing a local attacker to gain elevated privileges. The vulnerability carries a CVSS score of 7.8 (High), indicating a significant risk. It requires local access and low privileges, but no user interaction is needed, making it relatively easy to exploit once an attacker has a foothold. Successful exploitation could lead to high impact on confidentiality, integrity, and availability of the affected system. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. While it has received some community discussion and media coverage, it is not listed on the CISA KEV catalog and is considered inactive on the Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
1709CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:* | ||
1803CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:* | ||
1809CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.