Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2020-1113 |
CWE-ID | CWE-345 |
Exploitation vector | Local network |
Public exploit | N/A |
Vulnerable software |
Windows Operating systems & Components / Operating system Windows Server Operating systems & Components / Operating system |
Vendor | Microsoft |
Security Bulletin
This security bulletin contains one medium risk vulnerability.
EUVDB-ID: #VU27842
Risk: Medium
CVSSv4.0: 6.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2020-1113
CWE-ID:
CWE-345 - Insufficient Verification of Data Authenticity
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists in Microsoft Windows when the Task Scheduler service fails to properly verify client connections over RPC.A remote attacker on the local network can perform a man-in-the-Middle (MitM) attack and execute arbitrary code on the target system.
Install update from vendor's website.
Vulnerable software versionsWindows: 7 - 10 1909 10.0.18363.476
Windows Server: 2008 - 2019 1909
CPE2.3https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1113
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the local network (LAN).
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.