ZeroHour

CVE-2020-1054

KEV PoC mass

Privilege Escalation in Microsoft Windows Win32k Kernel Driver (CVE-2020-1054)

CISA: Microsoft Win32k Privilege Escalation Vulnerability

CVSS 3.1
7.0 high
EPSS
54%p99
Published
()
KEV added
AI analysis

CVE-2020-1054 is an elevation-of-privilege flaw (CWE-787, an out-of-bounds memory access) in the Windows kernel-mode driver (win32k), which fails to properly handle objects in memory. To exploit it, an attacker who can already log on to an affected Windows machine must run a specially crafted application, which triggers the memory-handling error and allows arbitrary code execution in kernel mode. Successful exploitation effectively yields full SYSTEM-level control of the host: the attacker can install programs, view, change or delete any data, and create new accounts with full user rights. Affected products per the CPE data are Windows 7, 8.1, RT 8.1, Windows 10 versions 1507 through 1909, and Windows Server 1803 and 1903. The flaw was fixed in Microsoft's May 2020 Patch Tuesday, a public DrawIconEx-based local privilege escalation PoC exists, EPSS is 54.2% (99th percentile), and CISA added it to the KEV catalog on 2021-11-03, confirming exploitation in the wild; related threat reporting around this CVE ties it to malware campaigns such as PurpleFox and Raspberry Robin, while ransomware use is listed as unknown.

What to do: Apply Microsoft's May 2020 security updates (or any later cumulative update) to Windows 7, 8.1, RT 8.1, Windows 10 1507–1909, and Windows Server 1803/1903, per the CISA KEV required action; prioritize multi-user hosts such as RDS servers where low-privileged users can run code. For legacy systems that no longer receive updates (e.g., Windows 7/8.1 post-EOL), limit local logon and software-execution rights for untrusted users and monitor for local privilege escalation activity.

Affected
microsoft Windows 101507, 1607, 1709, 1803, 1809, 1903, 1909
microsoft Windows 7
microsoft Windows 8.1
microsoft Windows RT 8.1
microsoft Windows Server 18031803
microsoft Windows Server 19031903
Estimated exposure
mass≈1 billion Windows devices (global Windows 10 install base plus the legacy Windows 7/8.1 estate) — The flaw resides in the win32k kernel-mode driver present in essentially every Windows 7 through Windows 10 client deployment, so the affected population tracks the global Windows install base (Windows 10 alone surpassed 1 billion active…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. The update addresses this vulnerability by correcting how the Windows kernel-mode driver handles objects in memory.

CISA Known Exploited Vulnerability
Affected
Microsoft Win32k
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows 10 1909, windows 7, windows 8.1, windows rt 8.1, windows server 1803, windows server 1903
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news