peter bassill · operator
$ cve CVE-2020-1054 JSON

CVE-2020-1054 KEV

7.0
HIGH · CVSS 3.1 · EPSS 54.2% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-03.

Description

An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. The update addresses this vulnerability by correcting how the Windows kernel-mode driver handles objects in memory.

Scoring

CVSS7.0 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS54.16% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-787
On CISA KEVyes — remediate by 2022-05-03
Public exploitnone known
Published2020-05-21
Last modified2026-08-19

CISA KEV

NameMicrosoft Win32k Privilege Escalation Vulnerability
Added2021-11-03
Due2022-05-03
Vendor / productMicrosoft / Win32k
Ransomware usenone reported

Affected (17)

VendorProduct
microsoftwindows 10 1507
microsoftwindows 10 1607
microsoftwindows 10 1709
microsoftwindows 10 1803
microsoftwindows 10 1809
microsoftwindows 10 1903
microsoftwindows 10 1909
microsoftwindows 7
microsoftwindows 8.1
microsoftwindows rt 8.1
microsoftwindows server 1803
microsoftwindows server 1903
microsoftwindows server 1909
microsoftwindows server 2008
microsoftwindows server 2012
microsoftwindows server 2016
microsoftwindows server 2019

References

→ the Explorer  ·  watch your stack  ·  NVD