CVE-2020-16935: Windows COM Server Elevation of Privilege Vulnerability
<p>An elevation of privilege vulnerability exists when Windows improperly handles COM object creation. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges.</p> <p>To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.</p> <p>The update addresses the vulnerability by correcting how the Windows COM Server creates COM objects.</p>
Other sources
An elevation of privilege vulnerability exists when Windows improperly handles COM object creation, aka 'Windows COM Server Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-16916.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-16935?
CVE-2020-16935 has a severity rating categorized as 'Important' by Microsoft.
How do I fix CVE-2020-16935?
To fix CVE-2020-16935, update your affected Microsoft Windows version to the latest security patch provided by Microsoft.
What versions of Windows are affected by CVE-2020-16935?
CVE-2020-16935 affects multiple versions of Windows, including Windows 7, Windows 8.1, Windows 10, and various Windows Server editions.
What does CVE-2020-16935 exploit involve?
CVE-2020-16935 involves an elevation of privilege vulnerability due to improper handling of COM object creation.
Can CVE-2020-16935 allow arbitrary code execution?
Yes, successful exploitation of CVE-2020-16935 can allow an attacker to run arbitrary code with elevated privileges.