ZeroHour

CVE-2020-1027

KEV PoC mass

Windows Kernel Heap Buffer Overflow Enables Local Privilege Escalation (CVE-2020-1027)

CISA: Microsoft Windows Kernel Privilege Escalation Vulnerability

CVSS 3.1
7.8 high
EPSS
5%p91
Published
()
KEV added
AI analysis

CVE-2020-1027 is a local elevation-of-privilege vulnerability in the Windows kernel caused by an out-of-bounds write (CWE-787) in how the kernel handles objects in memory; the referenced public proof of concept characterizes the flaw as a heap buffer overflow in the Windows sxs component's XML parsing of assembly manifest ('assemblyIdentity') data. An attacker with low privileges on a targeted system can trigger the memory corruption without user interaction, typically by causing crafted assembly/manifest content to be parsed. Successful exploitation elevates the attacker to kernel privileges, giving full control of the host with high confidentiality, integrity, and availability impact. All Windows 7, 8.1, RT 8.1, Windows 10 versions 1507 through 1909, and Windows Server 1803 and 1903 installations were in scope when the flaw was disclosed. The bug was actively exploited at the time it was patched: April 2020 Patch Tuesday reporting describes it among three Windows issues exploited in the wild, Google Project Zero tied it to a sophisticated hacking campaign that used 11 zero-days, CISA added it to the KEV catalog on 2022-05-23, and EPSS currently estimates a 4.5% probability of exploitation within 30 days.

What to do: Apply the April 2020 Windows security updates (or any later cumulative update) to every affected Windows 7, 8.1, RT 8.1, Windows 10 1507-1909, and Windows Server 1803/1903 system, per vendor instructions; CISA's KEV listing makes patching this CVE mandatory for federal agencies. Because exploitation requires local code execution, prioritize multi-user and internet-exposed hosts such as RDS/session servers, VDI, and jump hosts, and anywhere unprivileged users can run untrusted code. Most affected versions are now past end of support, so any system that cannot receive the patch should be migrated to a supported Windows release, and remediation should be verified by confirming the April 2020 or later cumulative update is installed on each host.

Affected
Microsoft Windows 101507, 1607, 1709, 1803, 1809, 1903, 1909
Microsoft Windows 7all supported versions at time of disclosure
Microsoft Windows 8.1all supported versions at time of disclosure
Microsoft Windows RT 8.1all supported versions at time of disclosure
Microsoft Windows Server 1803all supported editions at time of disclosure
Microsoft Windows Server 1903all supported editions at time of disclosure
Estimated exposure
masshundreds of millions of devices (the affected Windows 7/8.1/10 versions accounted for the bulk of the roughly one-billion-device Windows installed base in 2020) — Windows 7, 8.1, and Windows 10 1507-1909 together represented the large majority of the Windows installed base at the April 2020 disclosure, so every unpatched system running one of those versions is plausibly affected.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0913, CVE-2020-1000, CVE-2020-1003.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows 10 1909, windows 7, windows 8.1, windows rt 8.1, windows server 1803, windows server 1903
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news