Back

HIGH

Microsoft Windows Elevation of Privilege Vulnerability

Published May 21, 2020

Description

An elevation of privilege vulnerability exists in Windows Block Level Backup Engine Service (wbengine) that allows file deletion in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. The update addresses the vulnerability by correcting how the Windows Block Level Backup Engine Service handles file operations.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (0)

No CWE recorded.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner microsoft
Published May 21, 2020
Updated Aug 19, 2026
Reserved Nov 4, 2019
NVD
Status Modified
Modified Aug 19, 2026
Red Hat
Severity n/a
Public date n/a