cbcvebase.
CVE-2020-0662
published 2020-02-11

CVE-2020-0662: A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'.

PriorityP357high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
13.25%
95.9th percentile
A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka 'Windows Remote Code Execution Vulnerability'.

Affected

49 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10_version_1903_for_x64-based_systems
microsoftwindows_10_version_1909_for_x64-based_systems
microsoftwindows_server
microsoftwindows_server
microsoftwindows_server
microsoftwindows_server
microsoftwindows_server
microsoftwindows_server
microsoftwindows_server
microsoftwindows_server
microsoftwindows_server
microsoftwindows_server

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerable service is Internet Connection Sharing (ICS). Monitor for memory corruption triggered by specially crafted packets sent to the ICS service, particularly targeting the DHCP server component.
  • Attack vector is network-based with no user interaction required. Monitor for unexpected or malformed DHCP packets sent to Windows hosts running ICS, especially from domain-authenticated users.
  • Successful exploitation results in arbitrary code execution with elevated privileges on the server. Monitor for anomalous child processes or privilege escalation events originating from the ICS service (svchost.exe hosting SharedAccess).
  • Exploitation requires only Domain User credentials and is network-accessible with no user interaction. Prioritize detection on all Windows servers and workstations exposed to domain users.
  • ·The impacted service was not disclosed in the original Microsoft bulletin but was later identified as Internet Connection Sharing (ICS). Scope detection accordingly to hosts with ICS enabled.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_msrc8.6HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.