CVE-2020-1010
Executive Summary
CVE-2020-1010 exposes an elevation‑of‑privilege flaw in Windows Block Level Backup Engine Service (wbengine). After local authentication, a malicious user can run a crafted application that deletes arbitrary files, effectively taking control of the system. The patch corrects file‑operation handling in wbengine. Not listed in CISA KEV.
Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2020-05-21T23:15:11.493 - Last Modified: 2026-08-19T17:17:08.133
Original Description: An elevation of privilege vulnerability exists in Windows Block Level Backup Engine Service (wbengine) that allows file deletion in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. The update addresses the vulnerability by correcting how the Windows Block Level Backup Engine Service handles file operations.
"What lies behind us and what lies before us are tiny matters compared to what lies within us."
— Walt Emerson