9.3

CVE-2020-1421

A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.

Data is provided by the National Vulnerability Database (NVD)
MicrosoftWindows 10 Version- HwPlatformx64
MicrosoftWindows 10 Version- HwPlatformx86
MicrosoftWindows 10 Version1607 HwPlatformx64
MicrosoftWindows 10 Version1607 HwPlatformx86
MicrosoftWindows 10 Version1709 HwPlatformarm64
MicrosoftWindows 10 Version1709 HwPlatformx64
MicrosoftWindows 10 Version1709 HwPlatformx86
MicrosoftWindows 10 Version1803 HwPlatformarm64
MicrosoftWindows 10 Version1803 HwPlatformx64
MicrosoftWindows 10 Version1803 HwPlatformx86
MicrosoftWindows 10 Version1809 HwPlatformarm64
MicrosoftWindows 10 Version1809 HwPlatformx64
MicrosoftWindows 10 Version1809 HwPlatformx86
MicrosoftWindows 10 Version1903 HwPlatformarm64
MicrosoftWindows 10 Version1903 HwPlatformx64
MicrosoftWindows 10 Version1903 HwPlatformx86
MicrosoftWindows 10 Version1909 HwPlatformarm64
MicrosoftWindows 10 Version1909 HwPlatformx64
MicrosoftWindows 10 Version1909 HwPlatformx86
MicrosoftWindows 10 Version2004 HwPlatformarm64
MicrosoftWindows 10 Version2004 HwPlatformx64
MicrosoftWindows 10 Version2004 HwPlatformx86
MicrosoftWindows Server 2016 Version1903
MicrosoftWindows Server 2016 Version1909
MicrosoftWindows Server 2016 Version2004
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 47.99% 0.974
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')

The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.