CVE-2020-1054
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
21/05/2020
Last modified:
04/04/2025
Description
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1143.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:x64:* | ||
cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:x86:* | ||
cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x64:* | ||
cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x86:* | ||
cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:arm64:* | ||
cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:x64:* | ||
cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:x86:* | ||
cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:arm64:* | ||
cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:x64:* | ||
cpe:2.3:o:microsoft:windows_10_1803:-:*:*:*:*:*:x86:* | ||
cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:arm64:* | ||
cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x64:* | ||
cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x86:* | ||
cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:arm64:* | ||
cpe:2.3:o:microsoft:windows_10_1903:-:*:*:*:*:*:x64:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://packetstormsecurity.com/files/160515/Microsoft-Windows-DrawIconEx-Local-Privilege-Escalation.html
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1054
- http://packetstormsecurity.com/files/160515/Microsoft-Windows-DrawIconEx-Local-Privilege-Escalation.html
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1054