Field Assessment
AI analysis pending.
CVE
CVE-2016-3067
Severity
CRITICAL
CVSS
9.8
EPSS
2.04%
Original Filing — NVD Description
Cygwin before 2.5.0 does not properly handle updating permissions when changing users, which allows attackers to gain privileges.