PT-2020-3904 · Microsoft · Windows Cloudexperiencehost+2
James Forshaw
·
Published
2020-09-08
·
Updated
2023-12-31
·
CVE-2020-1471
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Microsoft Windows CloudExperienceHost versions prior to the fixed version
Windows 10 versions 1909, 2004
Description:
An elevation of privilege issue exists due to the failure of Microsoft Windows CloudExperienceHost to properly check COM objects. This could allow an attacker to gain elevated privileges on a targeted system by running a specially crafted script or application after logging on to the affected system.
Recommendations:
For Windows 10 versions 1909, 2004, apply the security update that addresses the vulnerability by checking COM objects.
For Microsoft Windows CloudExperienceHost, apply the security update that checks COM objects to resolve the issue.
As a temporary workaround, consider restricting access to COM objects until a patch is available.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows Cloudexperiencehost
Windows
Windows 10