CVE-2020-1118: Microsoft Windows Transport Layer Security Denial of Service Vulnerability
A denial of service vulnerability exists in the Windows implementation of Transport Layer Security (TLS) when it improperly handles certain key exchanges, aka 'Microsoft Windows Transport Layer Security Denial of Service Vulnerability'.
Other sources
A denial of service vulnerability exists in the Windows implementation of Transport Layer Security (TLS) when it improperly handles certain key exchanges. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this vulnerability, a remote unauthenticated attacker could send a specially crafted request to a target system utilizing TLS 1.2 or lower, triggering the system to automatically reboot. The update addresses the vulnerability by changing the way TLS key exchange messages are validated.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556812 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556799 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4551853 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556807
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1118?
CVE-2020-1118 has been rated as critical due to its potential to cause a denial of service.
How do I fix CVE-2020-1118?
To fix CVE-2020-1118, apply the latest security updates provided by Microsoft for the affected Windows versions.
What is the impact of CVE-2020-1118 on Windows systems?
The impact of CVE-2020-1118 is that it can lead to a denial of service, making the system unresponsive.
Which versions of Windows are affected by CVE-2020-1118?
CVE-2020-1118 affects specific versions of Windows 10 and Windows Server 2019, including 1709, 1803, 1809, 1903, and 1909.
Is there any workaround for CVE-2020-1118?
Microsoft advises users to implement security updates as the primary method to mitigate CVE-2020-1118, and no specific workarounds are provided.