CVE-2020-1119
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2020
Last modified:
23/02/2026
Description
An information disclosure vulnerability exists when StartTileData.dll improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.<br />
To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.<br />
The update addresses the vulnerability by correcting the way in which StartTileData.dll handles objects in memory.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:microsoft:windows_10:1903:*:*:*:*:*:*:* | ||
| cpe:2.3:o:microsoft:windows_10:1909:*:*:*:*:*:*:* | ||
| cpe:2.3:o:microsoft:windows_10:2004:*:*:*:*:*:*:* | ||
| cpe:2.3:o:microsoft:windows_server_2016:1903:*:*:*:*:*:*:* | ||
| cpe:2.3:o:microsoft:windows_server_2016:1909:*:*:*:*:*:*:* | ||
| cpe:2.3:o:microsoft:windows_server_2016:2004:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



