Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilité · NVD

CVE-2020-1118

CVE-2020-1118 : sévérité high (CVSS 8.6). Aucune app du catalogue suivi n'est liée à cette CVE.

Gravité (CVSS)
8.6

Échelle NVD

Exploitation
14.7 %

EPSS, prédiction à 30 jours

Apps suivies
0
Encore exposées
0

EN A denial of service vulnerability exists in the Windows implementation of Transport Layer Security (TLS) when it improperly handles certain key exchanges. An attacker who successfully exploited the vulnerability could cause a target system to stop responding.
To exploit this vulnerability, a remote unauthenticated attacker could send a specially crafted request to a target system utilizing TLS 1.2 or lower, triggering the system to automatically reboot.
The update addresses the vulnerability by changing the way TLS key exchange messages are validated.

Vecteur d'attaque : Réseau Aucun privilège requis Sans interaction utilisateur
Voir le vecteur CVSS brut
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
EPSS 14.68% exploit modéré percentile 96.6%

Versions d'OS qui corrigent cette CVE

Cette CVE est corrigée par les releases de sécurité OS suivantes. Mettre l'OS à jour au moins vers la version indiquée.

Voir sur NVD ↗ Advisory · portal.msrc.microsoft.com