Risk | Low |
Patch available | YES |
Number of vulnerabilities | 3 |
CVE-ID | CVE-2020-0772 CVE-2020-0775 CVE-2020-0806 |
CWE-ID | CWE-119 CWE-200 CWE-264 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software Subscribe |
Windows Operating systems & Components / Operating system Windows Server Operating systems & Components / Operating system |
Vendor | Microsoft |
This security bulletin contains information about 3 vulnerabilities.
EUVDB-ID: #VU25949
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2020-0772
CWE-ID:
CWE-119 - Memory corruption
Exploit availability: No
DescriptionThe vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error when Windows Error Reporting improperly handles memory. A local user can use a specially crafted application to trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
MitigationInstall update from vendor's website.
Vulnerable software versionsWindows: 7 - 10 1909
Windows Server: 2008 - 2019 1909
http://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0772
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU25955
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2020-0775
CWE-ID:
CWE-200 - Information exposure
Exploit availability: No
DescriptionThe vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to incorrect handling of file operations in Windows Error Reporting. A local user can run a specially crafted application to gain access to sensitive information on the system.
Install updates from vendor's website.
Vulnerable software versionsWindows: 10 - 10 1909
Windows Server: 2016 - 2019 1909
http://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0775
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU25957
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2020-0806
CWE-ID:
CWE-264 - Permissions, Privileges, and Access Controls
Exploit availability: No
DescriptionThe vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists in Windows Error Reporting when handling and executing files. A local user can run a specially crafted application to execute arbitrary code on the system with elevated privileges.
Install updates from vendor's website.
Vulnerable software versionsWindows: 7 - 10 1909
Windows Server: 2008 R2 - 2019 1909
http://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0806
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?