CVE-2020-1123: Connected User Experiences and Telemetry Service Denial of Service Vulnerability
A denial of service vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Denial of Service Vulnerability'. This CVE ID is unique from CVE-2020-1084.
Other sources
A denial of service vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations. An attacker who successfully exploited this vulnerability could cause a system to stop responding. To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability. The security update addresses the vulnerability by correcting how the Connected User Experiences and Telemetry Service handles file operations.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556799 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556813 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556826 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556812 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4551853 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556807
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1123?
CVE-2020-1123 has a severity rating of important, indicating it can cause significant issues in affected systems.
What systems are affected by CVE-2020-1123?
CVE-2020-1123 affects various versions of Microsoft Windows 10 and Windows Server 2016 and 2019.
How do I fix CVE-2020-1123?
To fix CVE-2020-1123, ensure that your system is updated with the latest security patches from Microsoft.
What type of vulnerability is CVE-2020-1123?
CVE-2020-1123 is a denial of service vulnerability related to the Connected User Experiences and Telemetry Service.
Is CVE-2020-1123 exploitable remotely?
CVE-2020-1123 may be exploited by an attacker with local access to the system, making it less likely to be a remote threat.