CVE-2020-1286: Input Validation
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the current user, aka 'Windows Shell Remote Code Execution Vulnerability'.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1286?
CVE-2020-1286 has a CVSS base score of 8.8, indicating a high severity level.
How do I fix CVE-2020-1286?
To fix CVE-2020-1286, ensure your Windows operating system is updated with the latest security patches from Microsoft.
What systems are affected by CVE-2020-1286?
CVE-2020-1286 affects several versions of Windows 10 and Windows Server 2016, along with Windows Server 2019.
What type of attack does CVE-2020-1286 enable?
CVE-2020-1286 enables remote code execution attacks, allowing attackers to run arbitrary code in the context of the current user.
What happens if CVE-2020-1286 is successfully exploited?
If CVE-2020-1286 is successfully exploited, an attacker could take control of the affected system, potentially compromising sensitive data.