4.9
CVSSv2

CVE-2020-0728

Published: 11/02/2020 Updated: 18/02/2020
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

Microsoft Windows could allow a local authenticated malicious user to obtain sensitive information, caused by improper disclosure of file information by the Modules Installer Service. By executing a specially-crafted program, an attacker could exploit this vulnerability to read all files on the system.

Vulnerability Trend

Affected Products

Vendor Product Versions
MicrosoftWindows 101607, 1709, 1803, 1809, 1903, 1909
MicrosoftWindows Server 2016-, 1803, 1903, 1909
MicrosoftWindows Server 2019-

Mailing Lists

The TrustedInstaller service running on the Windows operating system hosts a COM service called Sxs Store Class; its ISxsStore interface provides methods to install/uninstall assemblies via application manifests files into the WinSxS store These API methods were meant to be available for users with administrative privileges only, but the logic was ...
The TrustedInstaller service running on the Windows operating system hosts a COM service called Sxs Store Class; its ISxsStore interface provides methods to install/uninstall assemblies via application manifests files into the WinSxS store These API methods were meant to be available for users with administrative privileges only, but the logic was ...

Recent Articles

Microsoft Patch Tuesday – February 2020
Symantec Threat Intelligence Blog • Preethi Koroth • 12 Feb 2020

This month the vendor has patched 99 vulnerabilities, 13 of which are rated Critical.

Posted: 12 Feb, 202024 Min ReadThreat Intelligence SubscribeMicrosoft Patch Tuesday – February 2020This month the vendor has patched 99 vulnerabilities, 13 of which are rated Critical.This month the vendor has patched 99 vulnerabilities, 13 of which are rated Critical.

As always, customers are advised to follow these security best practices:


Install vendor patches as soon as they are available.
Run all so...