First published: Fri Sep 11 2020(Updated: )
<p>An information disclosure vulnerability exists when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.</p> <p>To exploit the vulnerability, an attacker would have to either log on locally to an affected system, or convince a locally authenticated user to execute a specially crafted application.</p> <p>The security update addresses the vulnerability by correcting how win32k handles objects in memory.</p>
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
=1607 | ||
=1607 | ||
=1709 | ||
=1803 | ||
=1809 | ||
=1903 | ||
=1909 | ||
=2004 | ||
=r2 | ||
=1903 | ||
=1909 | ||
=2004 | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 | ||
Microsoft Windows 10 | =1607 | |
Microsoft Windows 10 | =1607 | |
Microsoft Windows 10 | =1709 | |
Microsoft Windows 10 | =1803 | |
Microsoft Windows 10 | =1809 | |
Microsoft Windows 10 | =1903 | |
Microsoft Windows 10 | =1909 | |
Microsoft Windows 10 | =2004 | |
Microsoft Windows 8.1 | ||
Microsoft Windows 8.1 | ||
Microsoft Windows RT 8.1 | ||
Microsoft Windows Server 2012 | ||
Microsoft Windows Server 2012 | =r2 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2016 | =1903 | |
Microsoft Windows Server 2016 | =1909 | |
Microsoft Windows Server 2016 | =2004 | |
Microsoft Windows Server 2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-0941 is an information disclosure vulnerability in the win32k component of Microsoft Windows.
CVE-2020-0941 has a severity rating of medium with a CVSS score of 5.5.
CVE-2020-0941 affects various versions of Microsoft Windows, including Windows 10, Windows 8.1, Windows RT 8.1, and Windows Server.
CVE-2020-0941 allows an attacker to obtain sensitive information from the kernel incorrectly provided by the win32k component of Windows.
Microsoft has released security updates to address the CVE-2020-0941 vulnerability. It is recommended to install the latest updates.