CVE-2020-1438: High severity windows 10 vulnerability
An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1373, CVE-2020-1390, CVE-2020-1427, CVE-2020-1428.
Affected Software
Remediation
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
Exploitation is local: an attacker needs local access and low-level privileges on an affected Windows system. The CVSS vector indicates no user interaction is required, and successful exploitation can affect confidentiality, integrity, and availability.
Which Windows systems should be checked?
The affected software list includes Windows 7, Windows 8.1, Windows 10, Windows RT 8.1, and Windows Server 2008, 2012, 2016, and 2019. Organizations should identify systems running these products and determine whether the available patch has been applied.
What should teams do to remediate the vulnerability?
A patch is available. Apply the vendor-provided patch to affected systems; the provided data does not identify an alternative mitigation for systems that cannot be patched immediately.