Severity
7.8HIGHNVD
EPSS
0.4%
top 38.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 15
Latest updateAug 30

Description

An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0913, CVE-2020-1003, CVE-2020-1027.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages10 packages

CVEListV5microsoft/windows13 versions+12
NVDmicrosoft/windows4 versions+3
NVDmicrosoft/windows_106 versions+5
CVEListV5microsoft/windows_server15 versions+14

Patches

🔴Vulnerability Details

3
GHSA
freewvs's nested directory structure can interrupt scan2024-08-30
GHSA
GHSA-hjqq-v5qj-gf74: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr2022-05-24
CVEList
CVE-2020-1000: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr2020-04-15

💥Exploits & PoCs

22
Exploit-DB
TVT NVMS 1000 - Directory Traversal2020-04-13
Exploit-DB
SpotFTP-FTP Password Recover 2.4.8 - Denial of Service (PoC)2020-02-25
Exploit-DB
aSc TimeTables 2020.11.4 - Denial of Service (PoC)2020-02-25
Exploit-DB
Sysax Multi Server 5.50 - Denial of Service (PoC)2020-01-20
Exploit-DB
GTalk Password Finder 2.2.1 - 'Key' Denial of Service (PoC)2020-01-17

📋Vendor Advisories

25
Red Hat
argo-cd: Bypassing Rate Limit and Brute Force Protection Using Cache Overflow2024-03-18
Chrome
Stable Channel Update for Desktop: CVE-2021-305382021-05-25
Chrome
Stable Channel Update for Desktop: CVE-2021-211822021-03-02
Chrome
Stable Channel Update for Desktop: CVE-2021-211712021-03-02
Chrome
Stable Channel Update for Desktop: CVE-2021-211522021-02-16
CVE-2020-1000 — Improper Privilege Management | cvebase