CVE-2020-1427: High severity windows 10 vulnerability
An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1373, CVE-2020-1390, CVE-2020-1428, CVE-2020-1438.
Affected Software
Remediation
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this vulnerability?
Exploitation requires local access and low-level privileges; it does not require user interaction. The CVSS vector indicates an attacker must already be able to run code or otherwise act locally on the affected system.
Which Windows systems should be assessed?
The affected software list includes Windows 7, Windows 8.1, Windows 10, Windows RT 8.1, and Windows Server 2008, 2012, 2016, and 2019. Systems running one of these listed products should be evaluated for the available patch.
What is the recommended remediation?
A patch is available. Applying the vendor-provided patch is the documented remediation.