CVE-2020-1068: Microsoft Windows Elevation of Privilege Vulnerability
An elevation of privilege vulnerability exists in Windows Media Service that allows file creation in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. The update addresses the vulnerability by correcting how the Windows Media Service handles file creation.
Other sources
An elevation of privilege vulnerability exists in Windows Media Service that allows file creation in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1010, CVE-2020-1079.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556799 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556813 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556826 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556812 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4551853 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556807
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1068?
CVE-2020-1068 has a CVSS score indicating it is an elevation of privilege vulnerability.
How do I fix CVE-2020-1068?
To fix CVE-2020-1068, apply the latest security updates provided by Microsoft for your affected version.
Which systems are affected by CVE-2020-1068?
CVE-2020-1068 affects multiple versions of Microsoft Windows 10 and Windows Server 2016 and 2019.
What are the potential impacts of exploiting CVE-2020-1068?
Exploiting CVE-2020-1068 allows an attacker to create files in arbitrary locations, which may lead to further system compromise.
Is authentication required to exploit CVE-2020-1068?
Yes, an attacker must first log on to the system to exploit CVE-2020-1068.