Attacker Value
Moderate
(1 user assessed)
Exploitability
High
(1 user assessed)
User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
0

AppInfo AiCheckSecureApplicationDirectory Bypass

Last updated February 13, 2020
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

The AppInfo service handles requests for UAC elevation. There’s an issue with the checking of secure directories which allows a user to install a UIAccess application without requiring full access to a secure directory leading to the potential for EoP

Add Assessment

1
Ratings
  • Attacker Value
    Medium
  • Exploitability
    High

General Information

Additional Info

Technical Analysis