Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

KEV · Activement exploitée

CVE-2020-1054

CVE-2020-1054 est activement exploitée (catalogue CISA KEV) : sévérité high (CVSS 7.0), 0 apps suivies concernées, aucune encore exposée en version courante.

Gravité (CVSS)
7.0

Échelle NVD

Exploitation
Avérée

CISA KEV · EPSS prédit 54.2 %

Apps suivies
0
Encore exposées
0

EN An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.
The update addresses this vulnerability by correcting how the Windows kernel-mode driver handles objects in memory.

Vecteur d'attaque : Local Sans interaction utilisateur
Voir le vecteur CVSS brut
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS 54.16% modèle prédictif ; la CISA constate une exploitation avérée percentile 99.0%

CISA Known Exploited Vulnerability

Ajouté au KEV
2021-11-03
Deadline remédiation
2022-05-03
Action requise
Apply updates per vendor instructions.
Ransomware
Inconnu (non documenté par CISA)

Versions d'OS qui corrigent cette CVE

Cette CVE est corrigée par les releases de sécurité OS suivantes. Mettre l'OS à jour au moins vers la version indiquée.

Voir sur NVD ↗ Catalogue CISA KEV ↗ Advisory · msrc.microsoft.com Advisory · portal.msrc.microsoft.com