PT-2020-3904 · Microsoft · Windows Cloudexperiencehost+2

James Forshaw

·

Published

2020-09-08

·

Updated

2023-12-31

·

CVE-2020-1471

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Microsoft Windows CloudExperienceHost versions prior to the fixed version Windows 10 versions 1909, 2004
Description: An elevation of privilege issue exists due to the failure of Microsoft Windows CloudExperienceHost to properly check COM objects. This could allow an attacker to gain elevated privileges on a targeted system by running a specially crafted script or application after logging on to the affected system.
Recommendations: For Windows 10 versions 1909, 2004, apply the security update that addresses the vulnerability by checking COM objects. For Microsoft Windows CloudExperienceHost, apply the security update that checks COM objects to resolve the issue. As a temporary workaround, consider restricting access to COM objects until a patch is available.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04297
CVE-2020-1471

Affected Products

Windows Cloudexperiencehost
Windows
Windows 10