CVE-2020-1153: Microsoft Graphics Components Remote Code Execution Vulnerability
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka 'Microsoft Graphics Components Remote Code Execution Vulnerability'.
Other sources
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a user would have to open a specially crafted file. The security update addresses the vulnerability by correcting how Microsoft Graphics Components handle objects in memory.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556846 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556843 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556852 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556853 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556854 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556813 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556826 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556799 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556812 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556807 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4551853
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1153?
CVE-2020-1153 has a severity rating of critical, indicating a high risk of remote code execution.
How do I fix CVE-2020-1153?
To fix CVE-2020-1153, users should apply the latest security updates provided by Microsoft for their affected systems.
What are the affected systems for CVE-2020-1153?
CVE-2020-1153 affects multiple versions of Microsoft Windows, including Windows 10, Windows 7, Windows 8.1, and various Windows Server editions.
Can CVE-2020-1153 be exploited remotely?
Yes, CVE-2020-1153 can be exploited remotely, allowing attackers to execute arbitrary code on vulnerable systems.
What type of vulnerability is CVE-2020-1153?
CVE-2020-1153 is classified as a remote code execution vulnerability within Microsoft Graphics Components.