CVE-2020-17074: Windows Update Orchestrator Service Elevation of Privilege Vulnerability
Published Nov 11, 2020
·Updated
Windows Update Orchestrator Service Elevation of Privilege Vulnerability
Affected Software
8 affected components
Microsoft Windows 10=20h2
Microsoft Windows 10=1903
Microsoft Windows 10=1909
Microsoft Windows 10=2004
Microsoft Windows Server 2016=20h2
Microsoft Windows Server 2016=1903
Microsoft Windows Server 2016=1909
Microsoft Windows Server 2016=2004
Remediation
Event History
Nov 11, 2020
CVE Published
06:48 AM
Data Sourced
06:48 AM
DescriptionSeverity
Data Sourced
via NVD·07:15 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-17074?
The severity of CVE-2020-17074 is rated as important, indicating a significant potential for exploitation.
2
How do I fix CVE-2020-17074?
To fix CVE-2020-17074, install the latest security updates from Microsoft for affected Windows versions.
3
What systems are affected by CVE-2020-17074?
CVE-2020-17074 affects multiple versions of Windows 10 and Windows Server 2016, specifically versions 1903, 1909, 2004, and 20H2.
4
What type of vulnerability is CVE-2020-17074?
CVE-2020-17074 is classified as an elevation of privilege vulnerability in the Windows Update Orchestrator Service.
5
Can CVE-2020-17074 be exploited remotely?
CVE-2020-17074 requires local access for exploitation, meaning a user must be logged into the system for the vulnerability to be exploited.