CVE-2020-16889: Windows KernelStream Information Disclosure Vulnerability
<p>An information disclosure vulnerability exists when the Windows KernelStream improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.</p> <p>To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would not allow an attacker to execute code or to elevate user rights directly, but it could be used to obtain information that could be used to try to further compromise the affected system.</p> <p>The update addresses the vulnerability by correcting how the Windows KernelStream handles objects in memory.</p>
Other sources
An information disclosure vulnerability exists when the Windows KernelStream improperly handles objects in memory, aka 'Windows KernelStream Information Disclosure Vulnerability'.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-16889?
CVE-2020-16889 is rated as a medium severity vulnerability due to its information disclosure potential.
How do I fix CVE-2020-16889?
To fix CVE-2020-16889, apply the latest security updates provided by Microsoft for affected versions of Windows.
Which systems are affected by CVE-2020-16889?
CVE-2020-16889 affects Microsoft Windows 7, Windows 8.1, Windows 10, and various Windows Server versions.
What type of vulnerability is CVE-2020-16889?
CVE-2020-16889 is an information disclosure vulnerability in the Windows Kernel, which can expose sensitive data.
Can CVE-2020-16889 be exploited remotely?
An attacker can exploit CVE-2020-16889 locally to obtain sensitive information but requires access to the vulnerable system.