9.3
CVE-2020-1412
- EPSS 22.58%
- Veröffentlicht 14.07.2020 23:15:17
- Zuletzt bearbeitet 21.11.2024 05:10:27
- Quelle secure@microsoft.com
- Teams Watchlist Login
- Unerledigt Login
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 10 Version- HwPlatformx64
Microsoft ≫ Windows 10 Version- HwPlatformx86
Microsoft ≫ Windows 10 Version1607 HwPlatformx64
Microsoft ≫ Windows 10 Version1607 HwPlatformx86
Microsoft ≫ Windows 10 Version1709 HwPlatformarm64
Microsoft ≫ Windows 10 Version1709 HwPlatformx64
Microsoft ≫ Windows 10 Version1709 HwPlatformx86
Microsoft ≫ Windows 10 Version1803 HwPlatformarm64
Microsoft ≫ Windows 10 Version1803 HwPlatformx64
Microsoft ≫ Windows 10 Version1803 HwPlatformx86
Microsoft ≫ Windows 10 Version1809 HwPlatformarm64
Microsoft ≫ Windows 10 Version1809 HwPlatformx64
Microsoft ≫ Windows 10 Version1809 HwPlatformx86
Microsoft ≫ Windows 10 Version1903 HwPlatformarm64
Microsoft ≫ Windows 10 Version1903 HwPlatformx64
Microsoft ≫ Windows 10 Version1903 HwPlatformx86
Microsoft ≫ Windows 10 Version1909 HwPlatformarm64
Microsoft ≫ Windows 10 Version1909 HwPlatformx64
Microsoft ≫ Windows 10 Version1909 HwPlatformx86
Microsoft ≫ Windows 10 Version2004 HwPlatformarm64
Microsoft ≫ Windows 10 Version2004 HwPlatformx64
Microsoft ≫ Windows 10 Version2004 HwPlatformx86
Microsoft ≫ Windows 8.1 Version- HwPlatformx64
Microsoft ≫ Windows 8.1 Version- HwPlatformx86
Microsoft ≫ Windows Rt 8.1 Version-
Microsoft ≫ Windows Server 2008 Version- Updatesp2 HwPlatformx64
Microsoft ≫ Windows Server 2008 Version- Updatesp2 HwPlatformx86
Microsoft ≫ Windows Server 2012 Version-
Microsoft ≫ Windows Server 2012 Versionr2
Microsoft ≫ Windows Server 2016 Version-
Microsoft ≫ Windows Server 2016 Version1903
Microsoft ≫ Windows Server 2016 Version1909
Microsoft ≫ Windows Server 2016 Version2004
Microsoft ≫ Windows Server 2019 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 22.58% | 0.957 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.