CVE-2020-17087
KEVmass1Windows Kernel Buffer Overflow Enables Local Privilege Escalation (CVE-2020-17087)
CISA: Microsoft Windows Kernel Privilege Escalation Vulnerability
CVE-2020-17087 is a local elevation-of-privilege flaw in the Windows kernel caused by an incorrect buffer size calculation (CWE-131), producing a kernel buffer overflow; public analyses from Microsoft and Google's disclosure place the vulnerable code in the kernel's cryptographic driver (cng.sys). A local attacker with low privileges can trigger the overflow without user interaction, gaining code execution in kernel context and effectively full control of the host (high impact on confidentiality, integrity, and availability; CVSS 7.8). Every Windows system on the affected builds is exposed: Windows 10 versions 1507 through 20H2, Windows 7, 8.1, RT 8.1, and Windows Server 2008, which at disclosure meant essentially the entire supported Windows install base. The flaw was exploited as a zero-day in the wild: Google disclosed its use in targeted attacks, reportedly chained with a Chrome zero-day, and CISA added it to the KEV catalog on 2021-11-03; EPSS currently estimates a 5.4% probability of exploitation within 30 days (92nd percentile), with ransomware association listed as unknown.
What to do: Apply Microsoft's November 2020 Patch Tuesday security updates to all affected Windows 10, Windows 7, 8.1, RT 8.1, and Windows Server 2008 systems; this is CISA's required action for the KEV listing and no official workaround is known. Prioritize hosts where untrusted users can log on locally or via RDP, and ensure Chromium-based browsers are fully updated since this kernel bug was reportedly chained with a Chrome zero-day. After patching, verify the November 2020 update is installed; treat any ransomware association as currently unconfirmed.
| microsoft Windows 10 | 1507, 1607, 1803, 1809, 1903, 1909, 2004, 20H2 |
| microsoft Windows 7 | — |
| microsoft Windows 8.1 | — |
| microsoft Windows RT 8.1 | — |
| microsoft Windows Server 2008 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows Kernel Local Elevation of Privilege Vulnerability
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1803, windows 10 1809, windows 10 1903, windows 10 1909, windows 10 2004, windows 10 20h2, windows 7, windows 8.1, windows rt 8.1, windows server 2008
- Weakness
- CWE-131
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H