---
id: CVE-2020-1086
title: >-
  An elevation of privilege vulnerability exists when the Windows Runtime
  improperly handles objects in memory
summary: >-
  An elevation of privilege vulnerability exists when the Windows Runtime
  improperly handles objects in memory. An attacker who successfully exploited
  this vulnerability could run arbitrary code in an elevated context.

  An attacker could ex…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
vendor: microsoft
product: windows_10
affected:
  - windows_10
  - windows_10 = 1607
  - windows_10 = 1709
  - windows_10 = 1803
  - windows_10 = 1809
  - windows_10 = 1903
  - windows_10 = 1909
  - windows_server_2016
  - windows_server_2019
  - windows_server_2019 = 1903
  - windows_server_2019 = 1909
published: '2020-05-21'
updated: '2026-08-19'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-1086'
references:
  - url: 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-1086'
    label: secure@microsoft.com
  - url: >-
      https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1086
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00833
epssPercentile: 0.56143
ingestedAt: '2026-08-19T17:42:37.651Z'
---

## Overview

An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context.
An attacker could exploit this vulnerability by running a specially crafted application on the victim system.
The update addresses the vulnerability by correcting the way the Windows Runtime handles objects in memory.

## Affected

- `windows_10`
- `windows_10 = 1607`
- `windows_10 = 1709`
- `windows_10 = 1803`
- `windows_10 = 1809`
- `windows_10 = 1903`
- `windows_10 = 1909`
- `windows_server_2016`
- `windows_server_2019`
- `windows_server_2019 = 1903`
- `windows_server_2019 = 1909`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
