Permissions, Privileges, and Access Controls in Microsoft Windows and Windows Server - CVE-2020-0754
Published: February 11, 2020 / Updated: June 3, 2020
Vulnerability identifier: #VU25218
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-0754
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to the way Windows Error Reporting (WER) handles and executes files. A local user can run a specially crafted application and gain elevated privileges on the target system.
Affected software
Microsoft Windows
Windows Server
Solutions Enabler Virtual Appliance
Solutions Enabler
Unisphere for PowerMax Virtual Appliance
Unisphere for PowerMax
Windows Server
Solutions Enabler Virtual Appliance
Solutions Enabler
Unisphere for PowerMax Virtual Appliance
Unisphere for PowerMax
How to mitigate CVE-2020-0754
Install updates from vendor's website.
Solutions Enabler Virtual Appliance - addressed in versions 9.0.0.19, 9.1.0.6
Solutions Enabler - addressed in versions 9.0.0.19, 9.1.0.6
Unisphere for PowerMax Virtual Appliance - addressed in versions 9.0.2.18, 9.1.0.17
Unisphere for PowerMax - addressed in versions 9.0.2.18, 9.1.0.17
Solutions Enabler - addressed in versions 9.0.0.19, 9.1.0.6
Unisphere for PowerMax Virtual Appliance - addressed in versions 9.0.2.18, 9.1.0.17
Unisphere for PowerMax - addressed in versions 9.0.2.18, 9.1.0.17
Links to Public Exploits and PoC-codes
- Exploit #2928 - CVE-2020-0753-and-CVE-2020-0754 (Writeup and POC for CVE-2020-0753, CVE-2020-0754 and six fixed Window DOS Vulnerabilities.) (June 3, 2020)
- Exploit #2212 - CVE-2020-0753-and-CVE-2020-0754 (Writeup and POC for CVE-2020-0753, CVE-2020-0754 and six unfixed Window DOS Vulnerabilities.) (March 18, 2020)