5.5

CVE-2020-1145

An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI)  handles objects in memory, allowing an attacker to retrieve information from a targeted system. By itself, the information disclosure does not allow arbitrary code execution; however, it could allow arbitrary code to be run if the attacker uses it in combination with another vulnerability.
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.
The security update addresses the vulnerability by correcting how GDI handles memory addresses.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 10 Version 1903
Microsoft ≫ Windows 10 Version 1909
Microsoft ≫ Windows Server 2016 Version 1903
Microsoft ≫ Windows Server 2016 Version 1909
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.88% 0.778
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Microsoft 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-1145
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1145
Patch
Vendor Advisory