SB2020061011 - Information disclosure in Windows Diagnostics & feedback
Published: June 10, 2020
Security Bulletin ID
SB2020061011
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2020-1296)
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to a boundary error within the Windows Diagnostics & feedback settings app. A local user can run a specially crafted program to trigger memory corruption and read contents of memory.Remediation
Install update from vendor's website.