An elevation of privilege vulnerability exists in the Local Security Authority Subsystem Service (LSASS) when an authenticated attacker sends a specially crafted authentication request. A remote attacker who successfully exploited this vulnerability could cause an elevation of privilege on the target system's LSASS service.
The security update addresses the vulnerability by changing the way that LSASS handles specially crafted authentication requests.
References
Link | Resource |
---|---|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1509 | Patch Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: microsoft
Published: 2020-08-17T19:13:19
Updated: 2024-05-29T16:32:24.869Z
Reserved: 2019-11-04T00:00:00
Link: CVE-2020-1509
JSON object: View
NVD Information
Status : Modified
Published: 2020-08-17T19:15:17.007
Modified: 2024-01-19T00:15:13.837
Link: CVE-2020-1509
JSON object: View
Redhat Information
No data.
CWE