CVE-2020-1136: Media Foundation Memory Corruption Vulnerability
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-1028, CVE-2020-1126, CVE-2020-1150.
Other sources
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit a malicious webpage. The security update addresses the vulnerability by correcting how Windows Media Foundation handles objects in memory.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556807 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556846 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556853 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556813 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556799 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556812 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556826 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4551853
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1136?
CVE-2020-1136 has a severity rating of important, indicating it may lead to vulnerabilities like memory corruption.
How do I fix CVE-2020-1136?
To fix CVE-2020-1136, you should apply the latest updates available for your affected Microsoft Windows operating system.
Which systems are affected by CVE-2020-1136?
CVE-2020-1136 affects various versions of Microsoft Windows, including Windows 10, Windows 8.1, and Windows Server versions.
What impact does CVE-2020-1136 have?
The impact of CVE-2020-1136 includes potential memory corruption which may allow for remote code execution.
Is there a workaround for CVE-2020-1136?
There is no specific workaround for CVE-2020-1136; applying security patches is the recommended action.