Information disclosure in Windows - CVE-2020-1459

 

Information disclosure in Windows - CVE-2020-1459

Published: August 12, 2020


Vulnerability identifier: #VU45608
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-1459
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Microsoft
Affected software:
Windows

Detailed vulnerability description

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application on ARM implementations that use speculative execution in control flow via a side-channel analysis, aka "straight-line speculation". A local user can use a specially crafted application and gain unauthorized access to sensitive information on the system.


How to mitigate CVE-2020-1459

Install updates from vendor's website.

Sources