CVE-2020-16916: Windows COM Server Elevation of Privilege Vulnerability
<p>An elevation of privilege vulnerability exists when Windows improperly handles COM object creation. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges.</p> <p>To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.</p> <p>The update addresses the vulnerability by correcting how the Windows COM Server creates COM objects.</p>
Other sources
An elevation of privilege vulnerability exists when Windows improperly handles COM object creation, aka 'Windows COM Server Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16935.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-16916?
CVE-2020-16916 is classified as an elevation of privilege vulnerability.
How do I fix CVE-2020-16916?
To fix CVE-2020-16916, apply the latest security updates provided by Microsoft for your affected Windows version.
Which versions of Windows are affected by CVE-2020-16916?
CVE-2020-16916 affects multiple versions of Windows, including Windows 7, 8.1, 10, and various Windows Server editions.
What could an attacker do by exploiting CVE-2020-16916?
An attacker exploiting CVE-2020-16916 could run arbitrary code with elevated privileges on an affected system.
How can I verify if my system is vulnerable to CVE-2020-16916?
You can verify if your system is vulnerable to CVE-2020-16916 by checking if it is running an affected version of Windows without the latest security updates.