CVE-2020-16907: Win32k Elevation of Privilege Vulnerability
<p>An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</p> <p>To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.</p> <p>The update addresses this vulnerability by correcting how the Windows kernel-mode driver handles objects in memory.</p>
Other sources
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16913.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-16907?
CVE-2020-16907 is rated as a high severity elevation of privilege vulnerability.
How do I fix CVE-2020-16907?
To mitigate CVE-2020-16907, it is recommended to apply the latest security updates from Microsoft.
Which Windows versions are affected by CVE-2020-16907?
CVE-2020-16907 affects Windows 10 versions 1709, 1803, 1809, 1903, 1909, 2004, and Windows Server versions 2016 and 2019.
What type of vulnerability is CVE-2020-16907?
CVE-2020-16907 is an elevation of privilege vulnerability resulting from the improper handling of objects in memory by the Windows kernel-mode driver.
What could an attacker do if they exploit CVE-2020-16907?
An attacker exploiting CVE-2020-16907 could run arbitrary code in kernel mode, potentially allowing them to install programs or view, change, or delete data.