CVE-2020-1154: Windows Common Log File System Driver Elevation of Privilege Vulnerability
An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory, aka 'Windows Common Log File System Driver Elevation of Privilege Vulnerability'.
Other sources
An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted application to take control over the affected system. The security update addresses the vulnerability by correcting how CLFS handles objects in memory.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556843 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556852 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556854 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556846 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556853 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556813 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556826 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556799 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556812 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4551853 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556807
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must first be able to log on to the affected system and run a specially crafted application. This is a local elevation-of-privilege issue rather than a remote unauthenticated attack.
What is the impact of successful exploitation?
A successful attacker could run processes in an elevated context and take control of the affected system.
Which systems should be reviewed for exposure?
Review systems running the listed affected products: Windows 7, Windows 10, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows Server 2016, and Windows Server 2019.
What remediation is identified?
Apply the security update that corrects how the Windows Common Log File System driver handles objects in memory.