<p>An elevation of privilege vulnerability exists when Microsoft Windows processes group policy updates. An attacker who successfully exploited this vulnerability could potentially escalate permissions or perform additional privileged actions on the target machine.</p>
<p>To exploit this vulnerability, an attacker would need to launch a man-in-the-middle (MiTM) attack against the traffic passing between a domain controller and the target machine. An attacker could then create a group policy to grant administrator rights to a standard user.</p>
<p>The security update addresses the vulnerability by enforcing Kerberos authentication for certain calls over LDAP.</p>
<p>To exploit this vulnerability, an attacker would need to launch a man-in-the-middle (MiTM) attack against the traffic passing between a domain controller and the target machine. An attacker could then create a group policy to grant administrator rights to a standard user.</p>
<p>The security update addresses the vulnerability by enforcing Kerberos authentication for certain calls over LDAP.</p>
Project Subscriptions
| Vendors | Products |
|---|---|
|
Microsoft
Subscribe
|
Windows 10
Subscribe
Windows 10 1507
Subscribe
Windows 10 1607
Subscribe
Windows 10 1803
Subscribe
Windows 10 1809
Subscribe
Windows 10 1909
Subscribe
Windows 7
Subscribe
Windows 8.1
Subscribe
Windows Rt 8.1
Subscribe
Windows Server 1903
Subscribe
Windows Server 1909
Subscribe
Windows Server 2004
Subscribe
Windows Server 2008
Subscribe
Windows Server 2008 R2
Subscribe
Windows Server 2008 Sp2
Subscribe
Windows Server 2012
Subscribe
Windows Server 2012 R2
Subscribe
Windows Server 2016
Subscribe
Windows Server 2019
Subscribe
|
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2024-08-04T06:25:00.644Z
Reserved: 2019-11-04T00:00:00
Link: CVE-2020-1013
No data.
Status : Modified
Published: 2020-09-11T17:15:17.857
Modified: 2024-11-21T05:09:33.500
Link: CVE-2020-1013
No data.
OpenCVE Enrichment
No data.
Weaknesses