7.2

CVE-2020-1071

An elevation of privilege vulnerability exists when Windows improperly handles errors tied to Remote Access Common Dialog. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges.
To exploit this vulnerability an attacker would need to physically access the booted machine to reach the logon screen. An attacker could then exploit the vulnerability and take control of an affected system.
The update addresses the vulnerability by correcting how the Windows handles errors tied to Remote Access Common Dialog.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 10 Version -
Microsoft ≫ Windows 10 Version 1607
Microsoft ≫ Windows 10 Version 1709
Microsoft ≫ Windows 10 Version 1803
Microsoft ≫ Windows 10 Version 1809
Microsoft ≫ Windows 10 Version 1903
Microsoft ≫ Windows 10 Version 1909
Microsoft ≫ Windows 7 Version - Update sp1
Microsoft ≫ Windows 8.1 Version -
Microsoft ≫ Windows Rt 8.1 Version -
Microsoft ≫ Windows Server 2008 Version - Update sp2
Microsoft ≫ Windows Server 2008 Version r2 Update sp1 HwPlatform itanium
Microsoft ≫ Windows Server 2008 Version r2 Update sp1 HwPlatform x64
Microsoft ≫ Windows Server 2019 Version 1903
Microsoft ≫ Windows Server 2019 Version 1909
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1% 0.603
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Microsoft 6.8 0.9 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
NIST 6.8 0.9 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-755 Improper Handling of Exceptional Conditions

The product does not handle or incorrectly handles an exceptional condition.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-1071
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1071
Patch
Vendor Advisory