ZeroHour
Cisco Talospublished ()ingested

Vulnerability Spotlight: Information disclosure in Windows 10 Kernel

highVulnerability exploited in the wildimportance 60CVE-2020-0791

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-0791
An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevati

An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0898.

NVD description · AI analysis pending
7.81%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
Full article239 words · extracted from blog.talosintelligence.com · click to collapse

Tuesday, March 10, 2020 13:23

Marcin Towalski of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.

Cisco Talos recently discovered an information disclosure vulnerability in the Windows 10 kernel. An attacker could exploit this vulnerability by tricking the victim into opening a specially crafted

executable, causing an out-of-bounds read, which leads to the disclosure of sensitive information.
Microsoft disclosed and patched this bug as part of their monthly security update Tuesday. For more on their updates, read the full blog here.

In accordance with our coordinated disclosure policy, Cisco Talos worked with Microsoft to ensure that these issues are resolved and that an update is available for affected customers.

Vulnerability details Microsoft Windows 10 Kernel SetMapMode MM_HIENGLISH information disclosure vulnerability (TALOS-2020-1016/CVE-2020-0791)

An exploitable information disclosure vulnerability exists in the kernel of Microsoft Windows 10. A specially crafted executable can cause an out-of-bounds read, resulting in information disclosure. To trigger this vulnerability, the attacker needs to execute a specially crafted executable.

Read the complete vulnerability advisory here for additional information.

Versions tested Talos tested and confirmed that the kernel in Microsoft Windows 10 is affected by this bug.

Coverage The following SNORTⓇ rules will detect exploitation attempts. Note that additional rules may be released at a future date and current rules are subject to change pending additional vulnerability information. For the most current rule information, please refer to your Firepower Management Center or Snort.org.

Snort Rules: 53257, 53258

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/vuln-spotlight-windows-10-kernel-information-disclosure/