7.8

CVE-2020-1077

An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context.
An attacker could exploit this vulnerability by running a specially crafted application on the victim system.
The update addresses the vulnerability by correcting the way the Windows Runtime handles objects in memory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 10 Version 1607
Microsoft ≫ Windows 10 Version 1709
Microsoft ≫ Windows 10 Version 1803
Microsoft ≫ Windows 10 Version 1809
Microsoft ≫ Windows 10 Version 1903
Microsoft ≫ Windows 10 Version 1909
Microsoft ≫ Windows Server 2019 Version 1903
Microsoft ≫ Windows Server 2019 Version 1909
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.84% 0.55
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Microsoft 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-1077
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1077
Patch
Vendor Advisory