CVE-2020-1084: Connected User Experiences and Telemetry Service Denial of Service Vulnerability
A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain function values. An attacker who successfully exploited this vulnerability could deny dependent security feature functionality. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The security update addresses the vulnerability by correcting how the Connected User Experiences and Telemetry Service validates certain function values.
Other sources
A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain function values.An attacker who successfully exploited this vulnerability could deny dependent security feature functionality.To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.The security update addresses the vulnerability by correcting how the Connected User Experiences and Telemetry Service validates certain function values., aka 'Connected User Experiences and Telemetry Service Denial of Service Vulnerability'. This CVE ID is unique from CVE-2020-1123.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556799 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556826 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556812 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4551853 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556807 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556813
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must be able to log on to an affected system and run a specially crafted application. The CVSS vector indicates local access and low privileges are required; no user interaction is required.
What is the practical impact of exploitation?
Successful exploitation can cause a denial of service affecting dependent security feature functionality. The provided CVSS assessment indicates availability impact, with no stated confidentiality or integrity impact.
Which systems are identified as affected?
The listed software includes Microsoft Windows 10, Microsoft Windows Server 2016, and Microsoft Windows Server 2019.
What fixes the issue?
The security update fixes the vulnerability by correcting validation of certain function values in the Connected User Experiences and Telemetry Service.