CVE-2016-3067

EUVD-2016-4140
Cygwin before 2.5.0 does not properly handle updating permissions when changing users, which allows attackers to gain privileges.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H