CVE-2020-16913: Win32k Elevation of Privilege Vulnerability
<p>An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</p> <p>To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.</p> <p>The update addresses this vulnerability by correcting how the Windows kernel-mode driver handles objects in memory.</p>
Other sources
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16907.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-16913?
CVE-2020-16913 has a severity rating of important as it allows an attacker to execute arbitrary code in kernel mode.
How do I fix CVE-2020-16913?
To fix CVE-2020-16913, you should apply the latest security updates provided by Microsoft for the affected Windows versions.
Which Windows versions are affected by CVE-2020-16913?
CVE-2020-16913 affects multiple versions of Windows 10 and Windows Server, specifically 1709, 1803, 1809, 1903, 1909, and 2004.
What can an attacker do by exploiting CVE-2020-16913?
An attacker exploiting CVE-2020-16913 can gain elevated privileges to run arbitrary code in kernel mode.
Is CVE-2020-16913 being actively exploited?
As of now, there is no public evidence that CVE-2020-16913 is being actively exploited, but it is crucial to apply patches as a precaution.