PT-2020-2918 · Microsoft · Windows 8.1+3

Netanel Ben-Simon

+1

·

Published

2020-06-09

·

Updated

2021-07-21

·

CVE-2020-1310

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows 10 versions 1607 through 1909 Windows 8.1 version 6.3
Description The issue is related to errors in handling objects in memory within the Win32k component of the Windows operating system. This can be exploited by an attacker to elevate their privileges using a specially crafted application. The vulnerability allows attackers to affect the system, potentially leading to an elevation of privileges.
Recommendations For Windows 10 versions 1607 through 1909, update to a version that includes the fix for this issue. For Windows 8.1 version 6.3, consider applying security patches or updates that address this specific problem as a temporary workaround, until a more permanent solution is available. As a general mitigation measure, restrict access to sensitive system components and ensure that all applications are run with the least privileges necessary to minimize the risk of exploitation.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03075
CVE-2020-1310

Affected Products

Win32K
Windows
Windows 10
Windows 8.1