ZeroHour

CVE-2020-1152

CVSS 3.1
5.8 medium
EPSS
<1%p47
Published
()
Modified
Description

An elevation of privilege vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system. To exploit the vulnerability, an attacker would have to log on to an affected system and run a specially crafted script or application. The update addresses the vulnerability by correcting how Windows handles calls to Win32k.

Vendors
microsoft
Products
windows 10, windows 8.1, windows rt 8.1, windows server 2012, windows server 2016, windows server 2019
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L

In the news

No ingested article mentions this CVE yet.