---
id: CVE-2020-1124
title: >-
  An elevation of privilege vulnerability exists when the Windows State
  Repository Service improperly handles objects in memory
summary: >-
  An elevation of privilege vulnerability exists when the Windows State
  Repository Service improperly handles objects in memory. An attacker who
  successfully exploited this vulnerability could run arbitrary code in an
  elevated context.

  An …
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
vendor: microsoft
product: windows_10
affected:
  - windows_10
  - windows_10 = 1607
  - windows_10 = 1709
  - windows_10 = 1803
  - windows_10 = 1809
  - windows_10 = 1903
  - windows_10 = 1909
  - windows_server_2016
  - windows_server_2016 = 1803
  - windows_server_2016 = 1903
  - windows_server_2016 = 1909
  - windows_server_2019
published: '2020-05-21'
updated: '2026-08-19'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-1124'
references:
  - url: 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-1124'
    label: secure@microsoft.com
  - url: >-
      https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1124
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00833
epssPercentile: 0.56108
ingestedAt: '2026-08-19T17:42:38.688Z'
---

## Overview

An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context.
An attacker could exploit this vulnerability by running a specially crafted application on the victim system.
The update addresses the vulnerability by correcting the way the Windows State Repository Service handles objects in memory.

## Affected

- `windows_10`
- `windows_10 = 1607`
- `windows_10 = 1709`
- `windows_10 = 1803`
- `windows_10 = 1809`
- `windows_10 = 1903`
- `windows_10 = 1909`
- `windows_server_2016`
- `windows_server_2016 = 1803`
- `windows_server_2016 = 1903`
- `windows_server_2016 = 1909`
- `windows_server_2019`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
