CVE-2020-1027
KEV PoC massWindows Kernel Heap Buffer Overflow Enables Local Privilege Escalation (CVE-2020-1027)
CISA: Microsoft Windows Kernel Privilege Escalation Vulnerability
CVE-2020-1027 is a local elevation-of-privilege vulnerability in the Windows kernel caused by an out-of-bounds write (CWE-787) in how the kernel handles objects in memory; the referenced public proof of concept characterizes the flaw as a heap buffer overflow in the Windows sxs component's XML parsing of assembly manifest ('assemblyIdentity') data. An attacker with low privileges on a targeted system can trigger the memory corruption without user interaction, typically by causing crafted assembly/manifest content to be parsed. Successful exploitation elevates the attacker to kernel privileges, giving full control of the host with high confidentiality, integrity, and availability impact. All Windows 7, 8.1, RT 8.1, Windows 10 versions 1507 through 1909, and Windows Server 1803 and 1903 installations were in scope when the flaw was disclosed. The bug was actively exploited at the time it was patched: April 2020 Patch Tuesday reporting describes it among three Windows issues exploited in the wild, Google Project Zero tied it to a sophisticated hacking campaign that used 11 zero-days, CISA added it to the KEV catalog on 2022-05-23, and EPSS currently estimates a 4.5% probability of exploitation within 30 days.
What to do: Apply the April 2020 Windows security updates (or any later cumulative update) to every affected Windows 7, 8.1, RT 8.1, Windows 10 1507-1909, and Windows Server 1803/1903 system, per vendor instructions; CISA's KEV listing makes patching this CVE mandatory for federal agencies. Because exploitation requires local code execution, prioritize multi-user and internet-exposed hosts such as RDS/session servers, VDI, and jump hosts, and anywhere unprivileged users can run untrusted code. Most affected versions are now past end of support, so any system that cannot receive the patch should be migrated to a supported Windows release, and remediation should be verified by confirming the April 2020 or later cumulative update is installed on each host.
| Microsoft Windows 10 | 1507, 1607, 1709, 1803, 1809, 1903, 1909 |
| Microsoft Windows 7 | all supported versions at time of disclosure |
| Microsoft Windows 8.1 | all supported versions at time of disclosure |
| Microsoft Windows RT 8.1 | all supported versions at time of disclosure |
| Microsoft Windows Server 1803 | all supported editions at time of disclosure |
| Microsoft Windows Server 1903 | all supported editions at time of disclosure |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0913, CVE-2020-1000, CVE-2020-1003.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows 10 1909, windows 7, windows 8.1, windows rt 8.1, windows server 1803, windows server 1903
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H