CVE-2020-1067: Windows Remote Code Execution Vulnerability
A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'.
Other sources
A remote code execution vulnerability exists in the way that Windows handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with elevated permissions on a target system. To exploit the vulnerability, an attacker who has a domain user account could create a specially crafted request, causing Windows to execute arbitrary code with elevated permissions. The security update addresses the vulnerability by correcting how Windows handles objects in memory.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556846 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556854 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556843 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556799 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556813 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556853 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556852 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556826 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556812 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4551853 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556807
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1067?
CVE-2020-1067 has a high severity rating due to its potential to allow remote code execution.
How do I fix CVE-2020-1067?
To fix CVE-2020-1067, install the latest security updates released by Microsoft for your affected Windows version.
Which systems are affected by CVE-2020-1067?
CVE-2020-1067 affects various versions of Microsoft Windows including Windows 7, Windows 8.1, Windows 10, and Windows Server editions.
What are the potential impacts of exploiting CVE-2020-1067?
Exploitation of CVE-2020-1067 may allow an attacker to execute arbitrary code on the affected system with elevated privileges.
Is there a workaround for CVE-2020-1067?
While the best course of action is to apply security updates, disabling certain features or restricting network access can reduce the risk associated with CVE-2020-1067.