CVE-2020-1428: High severity windows 10 vulnerability
An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1373, CVE-2020-1390, CVE-2020-1427, CVE-2020-1438.
Affected Software
Remediation
Event History
Frequently Asked Questions
What access does an attacker need to exploit this vulnerability?
Exploitation requires local access and low-privileged access on an affected Windows system. The CVSS vector indicates no user interaction is required, but it is not remotely exploitable through the network.
Which Windows systems should be assessed?
The vulnerability can affect Microsoft Windows 7, Windows 8.1, Windows 10, Windows RT 8.1, and Windows Server 2008, 2012, 2016, and 2019. The provided data does not identify specific editions, builds, or patch levels within those products.
What should be prioritized if remediation cannot be immediate?
Apply the available vendor patch. If patching cannot happen immediately, prioritize systems where untrusted or low-privileged users can obtain local access, since those users meet the stated prerequisite for exploitation.