CVE-2020-1413: High severity windows 10 vulnerability
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1249, CVE-2020-1353, CVE-2020-1370, CVE-2020-1399, CVE-2020-1404, CVE-2020-1414, CVE-2020-1415, CVE-2020-1422.
Affected Software
Remediation
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
Exploitation requires local access and existing low-privileged access to the affected system; the CVSS vector specifies AV:L and PR:L. No user interaction is required.
What is the likely impact of successful exploitation?
A successful exploit can elevate privileges and impact confidentiality, integrity, and availability; each is rated High in the supplied CVSS vector. This could allow an attacker with an existing local account to gain more extensive control of the system.
Which systems should be prioritized for remediation?
The affected software listed is Microsoft Windows 10, Microsoft Windows Server 2016, and Microsoft Windows Server 2019. A patch is available.