---
id: CVE-2020-1118
title: >-
  A denial of service vulnerability exists in the Windows implementation of
  Transport Layer Security (TLS) when it improperly handles certain key
  exchanges
summary: >-
  A denial of service vulnerability exists in the Windows implementation of
  Transport Layer Security (TLS) when it improperly handles certain key
  exchanges. An attacker who successfully exploited the vulnerability could
  cause a target syst…
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'
vendor: microsoft
product: windows_10
affected:
  - windows_10 = 1709
  - windows_10 = 1803
  - windows_10 = 1809
  - windows_10 = 1903
  - windows_10 = 1909
  - windows_server_2019
  - windows_server_2019 = 1903
  - windows_server_2019 = 1909
published: '2020-05-21'
updated: '2026-08-19'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-1118'
references:
  - url: 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-1118'
    label: secure@microsoft.com
  - url: >-
      https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1118
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.14681
epssPercentile: 0.96551
ingestedAt: '2026-08-19T17:42:38.580Z'
---

## Overview

A denial of service vulnerability exists in the Windows implementation of Transport Layer Security (TLS) when it improperly handles certain key exchanges. An attacker who successfully exploited the vulnerability could cause a target system to stop responding.
To exploit this vulnerability, a remote unauthenticated attacker could send a specially crafted request to a target system utilizing TLS 1.2 or lower, triggering the system to automatically reboot.
The update addresses the vulnerability by changing the way TLS key exchange messages are validated.

## Affected

- `windows_10 = 1709`
- `windows_10 = 1803`
- `windows_10 = 1809`
- `windows_10 = 1903`
- `windows_10 = 1909`
- `windows_server_2019`
- `windows_server_2019 = 1903`
- `windows_server_2019 = 1909`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
