KEV · Activement exploitée
CVE-2020-1054
CVE-2020-1054 est activement exploitée (catalogue CISA KEV) : sévérité high (CVSS 7.0), 0 apps suivies concernées, aucune encore exposée en version courante.
- Gravité (CVSS)
- 7.0
- Exploitation
- Avérée
- Apps suivies
- 0
- Encore exposées
- 0
Échelle NVD
CISA KEV · EPSS prédit 54.2 %
EN
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.
The update addresses this vulnerability by correcting how the Windows kernel-mode driver handles objects in memory.
Voir le vecteur CVSS brut
CISA Known Exploited Vulnerability
- Ajouté au KEV
- 2021-11-03
- Deadline remédiation
- 2022-05-03
- Action requise
- Apply updates per vendor instructions.
- Ransomware
- Inconnu (non documenté par CISA)
Versions d'OS qui corrigent cette CVE
Cette CVE est corrigée par les releases de sécurité OS suivantes. Mettre l'OS à jour au moins vers la version indiquée.
- Windows Server 2019 (Server Core installation) Corrigé dans -
- Windows Server 2019 Corrigé dans -
- Windows Server 2016 (Server Core installation) Corrigé dans -
- Windows Server 2016 Corrigé dans -
- Windows 10 1909 · 2019-09 Corrigé dans -
- Windows 10 1903 · 2019-03 Corrigé dans -
- Windows 10 1809 · 2018-09 Corrigé dans -
- Windows 10 1803 · 2018-03 Corrigé dans -
- Windows 10 1709 · 2017-09 Corrigé dans -
- Windows 10 1607 · 2016-07 Corrigé dans -