CVE-2020-1151: Windows Runtime Elevation of Privilege Vulnerability
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1077, CVE-2020-1086, CVE-2020-1090, CVE-2020-1125, CVE-2020-1139, CVE-2020-1149, CVE-2020-1155, CVE-2020-1156, CVE-2020-1157, CVE-2020-1158, CVE-2020-1164.
Other sources
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim system. The update addresses the vulnerability by correcting the way the Windows Runtime handles objects in memory.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556812 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556799 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4551853 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556807
Event History
Frequently Asked Questions
What does an attacker need to exploit this vulnerability?
An attacker needs to run a specially crafted application on the victim system. The CVSS vector indicates local attack access, no required privileges, and user interaction is required.
What is the impact of successful exploitation?
A successful attacker could run arbitrary code in an elevated context, affecting confidentiality, integrity, and availability.
Which systems are identified as affected?
The listed affected software includes Microsoft Windows 10, Microsoft Windows Server 2016, and Microsoft Windows Server 2019.
What mitigates the issue if updates cannot be applied immediately?
The provided information does not identify a workaround or mitigation. Reducing the ability for untrusted or specially crafted applications to be run on affected systems may limit the stated exploitation path.