5.5
CVE-2020-1391
- EPSS 1.22%
- Veröffentlicht 14.07.2020 23:15:15
- Zuletzt bearbeitet 21.11.2024 05:10:24
- Erkennungen
An information disclosure vulnerability exists when the Windows Agent Activation Runtime (AarSvc) fails to properly handle objects in memory, aka 'Windows Agent Activation Runtime Information Disclosure Vulnerability'.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 10 Version 1903
Microsoft ≫ Windows 10 Version 1909
Microsoft ≫ Windows 10 Version 2004
Microsoft ≫ Windows Server 2016 Version 1903
Microsoft ≫ Windows Server 2016 Version 1909
Microsoft ≫ Windows Server 2016 Version 2004
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.22% | 0.649 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| NIST | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:N
|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1391