CVE-2020-1067High· 7.8▾ TwilightA remote code execution vulnerability exists in the way that Windows handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with elevated permissions on a target system. To exploi…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0.5 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
9.5%
A remote code execution vulnerability exists in the way that Windows handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with elevated permissions on a target system. To exploit the vulnerability, an attacker who has a domain user account could create a specially crafted request, causing Windows to execute arbitrary code with elevated permissions. The security update addresses the vulnerability by correcting how Windows handles objects in memory.
windows_10windows_10 = 1607windows_10 = 1709windows_10 = 1803windows_10 = 1809windows_10 = 1903windows_10 = 1909windows_7windows_8.1windows_rt_8.1windows_server_2008windows_server_2008 = r2windows_server_2012windows_server_2012 = r2windows_server_2016windows_server_2016 = 1803windows_server_2016 = 1903windows_server_2016 = 1909windows_server_2019Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2020-1166High· 7.8An elevation of privilege vulnerability exists when Windows improperly handles calls to Clipboard Service
CVE-2020-1165High· 7.8An elevation of privilege vulnerability exists when Windows improperly handles calls to Clipboard Service
CVE-2020-1164High· 7.0An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory
CVE-2020-1158High· 7.8An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory
CVE-2020-1157High· 7.8An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory
CVE-2020-1156High· 7.8An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory