CVE-2020-1012
published 2020-09-11CVE-2020-1012: An elevation of privilege vulnerability exists in the way that the Wininit.dll handles objects in memory. An attacker who successfully exploited the…
PriorityP348high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
3.74%
88.6th percentile
An elevation of privilege vulnerability exists in the way that the Wininit.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
There are multiple ways an attacker could exploit the vulnerability:
In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit this vulnerability and then convince a user to view the website. An attacker would have no way to force users to view the attacker-controlled content. Instead, an attacker would have to convince users to take action, typically by getting them to click a link in an email message or in an Instant Messenger message that takes users to the attacker's website, or by opening an attachment sent through email.
In a file sharing attack scenario, an attacker could provide a specially crafted document file that is designed to exploit this vulnerability, and then convince a user to open the document file.
The security update addresses the vulnerability by ensuring the Wininit.dll properly handles objects in memory.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer_11 | >= 1.0.0 < publication | publication |
| msrc | internet_explorer_11 | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pqr6-x3hm-vw74: An elevation of privilege vulnerability exists in the way that the Wininit
ghsa_unreviewed·2022-05-24
CVE-2020-1012 [HIGH] CWE-269 GHSA-pqr6-x3hm-vw74: An elevation of privilege vulnerability exists in the way that the Wininit
An elevation of privilege vulnerability exists in the way that the Wininit.dll handles objects in memory, aka 'WinINet API Elevation of Privilege Vulnerability'.
Microsoft
WinINet API Elevation of Privilege Vulnerability
vendor_msrc·2020-09-08·CVSS 8.8
CVE-2020-1012 [HIGH] WinINet API Elevation of Privilege Vulnerability
WinINet API Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in the way that the Wininit.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
There are multiple ways an attacker could exploit the vulnerability:
In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit this vulnerability and then convince a user to view the website. An attacker would have no way to force users to view the attacker-controlled content. Instead, an attacker would have to convince users to take action, typically by getting them to click a link in an email message or in an Instant Messenger message that takes users to the attacker'
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-11864 libEMF: allows denial of service (issue 2 of 2)
bugzilla·2020-05-14·CVSS 5.5
CVE-2020-11864 [MEDIUM] CVE-2020-11864 libEMF: allows denial of service (issue 2 of 2)
CVE-2020-11864 libEMF: allows denial of service (issue 2 of 2)
libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows denial of service (issue 2 of 2).
Reference:
https://sourceforge.net/p/libemf/news/2020/05/re-release-of-libemf-1012/
Discussion:
Created libEMF tracking bugs for this issue:
Affects: fedora-all [bug 1835803]
---
External References:
https://sourceforge.net/p/libemf/news/2020/05/re-release-of-libemf-1012/
---
Statement:
libEMF is a C/C++ library which provides a drawing toolkit based on ECMA-234. The general purpose of this library is to create vector graphics files on POSIX systems which can be imported into OpenOffice.org or LibreOffice. Programs compiled with libEMF, output ECMA-234 graphics files locally which can be then imported into desktop applicati
Bugzilla
CVE-2020-11865 libEMF: allows out-of-bounds memory access
bugzilla·2020-05-14·CVSS 7.8
CVE-2020-11865 [HIGH] CVE-2020-11865 libEMF: allows out-of-bounds memory access
CVE-2020-11865 libEMF: allows out-of-bounds memory access
libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows out-of-bounds memory access.
Reference:
https://sourceforge.net/p/libemf/news/2020/05/re-release-of-libemf-1012/
Discussion:
Created libEMF tracking bugs for this issue:
Affects: fedora-all [bug 1835807]
---
Only F31 and older are affected. F32 has 1.0.12.
---
External References:
https://sourceforge.net/p/libemf/news/2020/05/re-release-of-libemf-1012/
---
Statement:
libEMF is a C/C++ library which provides a drawing toolkit based on ECMA-234. The general purpose of this library is to create vector graphics files on POSIX systems which can be imported into OpenOffice.org or LibreOffice. Programs compiled with libEMF, output ECMA-234 graphics files locally whic
Bugzilla
CVE-2020-11866 libEMF: allows a use-after-free
bugzilla·2020-05-14·CVSS 7.8
CVE-2020-11866 [HIGH] CVE-2020-11866 libEMF: allows a use-after-free
CVE-2020-11866 libEMF: allows a use-after-free
libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows a use-after-free.
Reference:
https://sourceforge.net/p/libemf/news/2020/05/re-release-of-libemf-1012/
Discussion:
Created libEMF tracking bugs for this issue:
Affects: fedora-all [bug 1835794]
---
External References:
https://sourceforge.net/p/libemf/news/2020/05/re-release-of-libemf-1012/
---
Statement:
libEMF is a C/C++ library which provides a drawing toolkit based on ECMA-234. The general purpose of this library is to create vector graphics files on POSIX systems which can be imported into OpenOffice.org or LibreOffice. Programs compiled with libEMF, output ECMA-234 graphics files locally which can be then imported into desktop applications. Therefore this use-after-fr
Bugzilla
CVE-2020-11863 libEMF: allows denial of service (issue 1 of 2)
bugzilla·2020-05-14·CVSS 5.5
CVE-2020-11863 [MEDIUM] CVE-2020-11863 libEMF: allows denial of service (issue 1 of 2)
CVE-2020-11863 libEMF: allows denial of service (issue 1 of 2)
libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows denial of service (issue 1 of 2).
Reference:
https://sourceforge.net/p/libemf/news/2020/05/re-release-of-libemf-1012/
Discussion:
Created libEMF tracking bugs for this issue:
Affects: fedora-all [bug 1835798]
---
External References:
https://sourceforge.net/p/libemf/news/2020/05/re-release-of-libemf-1012/
---
Statement:
libEMF is a C/C++ library which provides a drawing toolkit based on ECMA-234. The general purpose of this library is to create vector graphics files on POSIX systems which can be imported into OpenOffice.org or LibreOffice. Programs compiled with libEMF, output ECMA-234 graphics files locally which can be then imported into desktop applicati
2020-09-11
Published