Buffer overflow in Microsoft Windows and Windows Server - CVE-2020-17087
Published: October 31, 2020 / Updated: July 29, 2021
Vulnerability details
The vulnerability allows a local user to escalate privilege son the system.
The vulnerability exists due to a boundary error within the Windows Kernel Cryptography Driver cng.sys, which exposes a "\Device\CNG" device to user-mode programs and supports a variety of IOCTLs with non-trivial input structures. A local user can run a specially crafted program to trigger memory corruption and execute arbitrary code on the system with elevated privileges.
Note, this vulnerability is being actively exploited in the wild.
Affected software
Windows Server
Solutions Enabler Virtual Appliance
Solutions Enabler
Unisphere for PowerMax Virtual Appliance
Unisphere for PowerMax
How to mitigate CVE-2020-17087
Solutions Enabler - addressed in versions 9.1.0.17, 9.2.2.0
Unisphere for PowerMax Virtual Appliance - addressed in versions 9.1.0.28, 9.2.2.2
Unisphere for PowerMax - addressed in versions 9.1.0.28, 9.2.2.2
Links to Public Exploits and PoC-codes
- Exploit #6584 - Windows-Non-Paged-Pool-Overflow-Exploitation (Techniques based on named pipes for pool overflow exploitation targeting the most recent (and oldest) Windows versions demonstrated on CVE-2020-17087 and an off-by-one overflow) (July 29, 2021)
- Exploit #5493 - OHTS_IE6052-CVE-2020-17087 () (May 27, 2021)
- Exploit #4882 - CVE-2020-17087 (A CVE-2020-17087 PoC.) (November 30, 2020)
- Exploit #4773 - Issue 2104: Windows Kernel cng.sys pool-based buffer overflow in IOCTL 0x390400 (October 31, 2020)