ZeroHour

CVE-2020-0986

KEVmass1

Windows Kernel Out-of-Bounds Write Enables Local Privilege Escalation (CVE-2020-0986)

CISA: Microsoft Windows Kernel Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
16%p97
Published
()
KEV added
AI analysis

CVE-2020-0986 is an elevation of privilege vulnerability in the Microsoft Windows kernel caused by the kernel failing to properly handle objects in memory (classified as an out-of-bounds write, CWE-787). A local attacker who can already execute low-privileged code on a vulnerable machine can trigger the memory-corruption condition to elevate to SYSTEM/kernel-level privileges, gaining full read, write, and execution control over the system with no user interaction required. Affected deployments per the CPE data include Windows 8.1, Windows RT 8.1, Windows 10 versions 1507 through 2004, and Windows Server builds 1803 and 1903. CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2021-11-03, confirming exploitation in the wild, while any association with ransomware remains unknown. EPSS rates a 15.9% probability of exploitation within 30 days (97th percentile), and Microsoft patched the flaw in its April 2020 monthly security updates alongside a batch of similar Windows kernel privilege escalation vulnerabilities.

What to do: Apply Microsoft security updates for every affected release without delay (the fix shipped in the April 2020 monthly security updates, and the CISA KEV required action is to update per vendor instructions); verify installed cumulative updates rather than relying on KB numbers alone. Because this is a local privilege escalation used for post-compromise elevation, prioritize endpoints and multi-user hosts (RDS/VDI, remote workers) where untrusted users or already-executed malware run locally. There is no reliable workaround for a kernel memory-handling flaw, so patching is the primary mitigation.

Affected
Microsoft Windows 101507
Microsoft Windows 101607
Microsoft Windows 101709
Microsoft Windows 101803
Microsoft Windows 101809
Microsoft Windows 101903
Microsoft Windows 101909
Microsoft Windows 102004
Microsoft Windows 8.18.1
Microsoft Windows RT 8.1RT 8.1
Microsoft Windows Server (Semi-Annual Channel)1803
Microsoft Windows Server (Semi-Annual Channel)1903
Estimated exposure
massorder of 10^8: plausibly hundreds of millions of Windows installations across the affected 2015-2020 builds — Windows 10 alone had an installed base approaching one billion devices around the 2020 disclosure, and the affected list spans nearly all consumer and business Windows releases of that era plus Windows Server semi-annual channel builds…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2020-1266, CVE-2020-1269, CVE-2020-1273, CVE-2020-1274, CVE-2020-1275, CVE-2020-1276, CVE-2020-1307, CVE-2020-1316.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows 10 1909, windows 10 2004, windows 8.1, windows rt 8.1, windows server 1803, windows server 1903
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news