CVE-2020-1054: Microsoft Win32k Privilege Escalation Vulnerability
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1143.
Other sources
Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1054?
CVE-2020-1054 has a CVSS score indicating a high severity level due to its potential for elevation of privilege.
How can I mitigate CVE-2020-1054?
To mitigate CVE-2020-1054, apply the security update provided by Microsoft as soon as possible.
Which systems are affected by CVE-2020-1054?
CVE-2020-1054 affects multiple versions of Microsoft Windows 10, Windows 7, Windows 8.1, and various Windows Server editions.
Can CVE-2020-1054 be exploited remotely?
CVE-2020-1054 requires local access for exploitation, meaning an attacker needs to be on the system to take advantage of the vulnerability.
What type of vulnerability is CVE-2020-1054 classified as?
CVE-2020-1054 is classified as an elevation of privilege vulnerability.