PT-2020-3972 · Microsoft · Windows
Published
2020-08-09
·
Updated
2023-12-31
·
CVE-2020-0875
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Microsoft Windows versions (affected versions not specified)
Description:
The issue is related to errors in handling calls by the splwow64.exe executable file in Microsoft Windows operating systems. This could allow an attacker to obtain unauthorized access to protected information. The vulnerability itself does not enable arbitrary code execution but could be used in combination with other vulnerabilities to achieve this. For example, it could be combined with a remote code execution vulnerability or another elevation of privilege vulnerability to run arbitrary code with elevated privileges.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows