{"id":"CVE-2020-1084","title":"A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain function values.\nAn attacker who successfully exploited this vulnerability could deny dependent security feature fun…","summary":"A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain function values.\nAn attacker who successfully exploited this vulnerability could deny dependent security feature fun…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-20"],"vendor":"microsoft","product":"windows_10","affected":["windows_10","windows_10 = 1607","windows_10 = 1709","windows_10 = 1803","windows_10 = 1809","windows_10 = 1903","windows_10 = 1909","windows_server_2016","windows_server_2019"],"published":"2020-05-21","updated":"2026-08-19","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-1084","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-1084","label":"secure@microsoft.com"},{"url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1084","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01086,"epssPercentile":0.63352,"ingestedAt":"2026-08-19T17:42:37.614Z","slug":"CVE-2020-1084","body":"## Overview\n\nA Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain function values.\nAn attacker who successfully exploited this vulnerability could deny dependent security feature functionality.\nTo exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application.\nThe security update addresses the vulnerability by  correcting how the Connected User Experiences and Telemetry Service validates certain function values.\n\n## Affected\n\n- `windows_10`\n- `windows_10 = 1607`\n- `windows_10 = 1709`\n- `windows_10 = 1803`\n- `windows_10 = 1809`\n- `windows_10 = 1903`\n- `windows_10 = 1909`\n- `windows_server_2016`\n- `windows_server_2019`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}