CVE-2020-1126: Media Foundation Memory Corruption Vulnerability
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1028, CVE-2020-1136, CVE-2020-1150.
Other sources
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit a malicious webpage. The security update addresses the vulnerability by correcting how Windows Media Foundation handles objects in memory.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556799 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556813 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4551853 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556812 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556807
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1126?
CVE-2020-1126 is rated as important by Microsoft due to its potential impact on system stability and security.
How do I fix CVE-2020-1126?
To fix CVE-2020-1126, install the latest security updates provided by Microsoft for affected Windows versions.
Which versions of Windows are affected by CVE-2020-1126?
CVE-2020-1126 affects several versions of Windows 10, including 1607, 1709, 1803, 1809, 1903, 1909, as well as Windows Server 2016 and 2019.
What type of vulnerability is CVE-2020-1126?
CVE-2020-1126 is classified as a memory corruption vulnerability associated with improper handling of objects in memory by Windows Media Foundation.
Can CVE-2020-1126 be exploited remotely?
Yes, CVE-2020-1126 could potentially allow an attacker to execute arbitrary code remotely if a user opens a specially crafted media file.