CVE-2020-1047
published 2020-10-16CVE-2020-1047: An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory. An attacker who successfully…
PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.89%
55.3th percentile
An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory. An attacker who successfully exploited these vulnerabilities could gain elevated privileges on a target operating system.
This vulnerability by itself does not allow arbitrary code to be run. However, this vulnerability could be used in conjunction with one or more vulnerabilities (e.g. a remote code execution vulnerability and another elevation of privilege) that could take advantage of the elevated privileges when running.
The update addresses the vulnerabilities by correcting how Windows Hyper-V handles objects in memory.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1709 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1803 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1809 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_x64-based_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1909 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_2004 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2019 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_version_2004 | >= 10.0.0 < publication | publication |
| msrc | windows_10_version_1709_for_x64-based_systems | — | — |
| msrc | windows_10_version_1803_for_x64-based_systems | — | — |
| msrc | windows_10_version_1809_for_x64-based_systems | — | — |
| msrc | windows_10_version_1903_for_x64-based_systems | — | — |
| msrc | windows_10_version_1909_for_x64-based_systems | — | — |
| msrc | windows_10_version_2004_for_x64-based_systems | — | — |
| msrc | windows_server_2019 | — | — |
| msrc | windows_server_version_1903 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mq26-673p-77xj: An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory, aka 'Windows Hyper-V
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-1080 [HIGH] CWE-119 GHSA-mq26-673p-77xj: An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory, aka 'Windows Hyper-V
An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory, aka 'Windows Hyper-V Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1047.
GHSA
GHSA-cr49-gvqw-pcg9: An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory, aka 'Windows Hyper-V
ghsa_unreviewed·2022-05-24·CVSS 8.8
CVE-2020-1047 [HIGH] CWE-119 GHSA-cr49-gvqw-pcg9: An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory, aka 'Windows Hyper-V
An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory, aka 'Windows Hyper-V Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1080.
Microsoft
Windows Hyper-V Elevation of Privilege Vulnerability
vendor_msrc·2020-10-13·CVSS 7.8
CVE-2020-1047 [HIGH] Windows Hyper-V Elevation of Privilege Vulnerability
Windows Hyper-V Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when Windows Hyper-V on a host server fails to properly handle objects in memory. An attacker who successfully exploited these vulnerabilities could gain elevated privileges on a target operating system.
This vulnerability by itself does not allow arbitrary code to be run. However, this vulnerability could be used in conjunction with one or more vulnerabilities (e.g. a remote code execution vulnerability and another elevation of privilege) that could take advantage of the elevated privileges when running.
The update addresses the vulnerabilities by correcting how Windows Hyper-V handles objects in memory.
Windows Kernel: Windows Kernel
Issuing CNA: Microsoft
Impact: Elevatio
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-6105 f2fs-tools: specially crafted f2fs filesystem can cause Information overwrite resulting in a code execution
bugzilla·2020-10-15·CVSS 7.8
CVE-2020-6105 [HIGH] CVE-2020-6105 f2fs-tools: specially crafted f2fs filesystem can cause Information overwrite resulting in a code execution
CVE-2020-6105 f2fs-tools: specially crafted f2fs filesystem can cause Information overwrite resulting in a code execution
An exploitable code execution vulnerability exists in the multiple devices functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted f2fs filesystem can cause Information overwrite resulting in a code execution. An attacker can provide a malicious file to trigger this vulnerability.
Reference:
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1047
Discussion:
Created f2fs-tools tracking bugs for this issue:
Affects: epel-7 [bug 1888775]
Affects: fedora-all [bug 1888774]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the depend
Bugzilla
CVE-2018-14340 wireshark: Multiple dissectors could crash (wnpa-sec-2018-36)
bugzilla·2018-07-23·CVSS 7.5
CVE-2018-14340 [HIGH] CVE-2018-14340 wireshark: Multiple dissectors could crash (wnpa-sec-2018-36)
CVE-2018-14340 wireshark: Multiple dissectors could crash (wnpa-sec-2018-36)
It was found that dissectors that support zlib decompression could crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
Upstream bug(s):
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14675
External References:
https://www.wireshark.org/security/wnpa-sec-2018-36.html
Discussion:
Created wireshark tracking bugs for this issue:
Affects: fedora-all [bug 1607334]
---
Upstream patch:
https://code.wireshark.org/review/#/c/27561/2/epan/tvbuff_zlib.c
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1047 https://access.redhat.com/errata/RHSA-2020:1047
---
This bug is now closed. Further
Bugzilla
CVE-2018-14368 wireshark: Bazaar dissector infinite loop (wnpa-sec-2018-40)
bugzilla·2018-07-23·CVSS 7.5
CVE-2018-14368 [HIGH] CVE-2018-14368 wireshark: Bazaar dissector infinite loop (wnpa-sec-2018-40)
CVE-2018-14368 wireshark: Bazaar dissector infinite loop (wnpa-sec-2018-40)
It was found that Bazaar dissector could crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
Upstream bug(s):
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14841
External References:
https://www.wireshark.org/security/wnpa-sec-2018-40.html
Discussion:
Created wireshark tracking bugs for this issue:
Affects: fedora-all [bug 1607334]
---
Upstream patch:
https://code.wireshark.org/review/#/c/28228/2/epan/dissectors/packet-bzr.c
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1047 https://access.redhat.com/errata/RHSA-2020:1047
---
This bug is now closed. Further updates for indiv
Bugzilla
CVE-2018-14341 wireshark: DICOM dissector infinite loop (wnpa-sec-2018-39)
bugzilla·2018-07-23·CVSS 7.5
CVE-2018-14341 [HIGH] CVE-2018-14341 wireshark: DICOM dissector infinite loop (wnpa-sec-2018-39)
CVE-2018-14341 wireshark: DICOM dissector infinite loop (wnpa-sec-2018-39)
It was found that DICOM dissector could crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
Upstream bug(s):
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14742
External References:
https://www.wireshark.org/security/wnpa-sec-2018-39.html
Discussion:
Created wireshark tracking bugs for this issue:
Affects: fedora-all [bug 1607334]
---
Upstream patch:
https://code.wireshark.org/review/#/c/27853/2/epan/dissectors/packet-dcm.c
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1047 https://access.redhat.com/errata/RHSA-2020:1047
---
This bug is now closed. Further updates for individ
Bugzilla
CVE-2018-7418 wireshark: SIGCOMP dissector crash in packet-sigcomp.c
bugzilla·2018-02-26·CVSS 7.5
CVE-2018-7418 [HIGH] CVE-2018-7418 wireshark: SIGCOMP dissector crash in packet-sigcomp.c
CVE-2018-7418 wireshark: SIGCOMP dissector crash in packet-sigcomp.c
A flaw was found in Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the SIGCOMP dissector could crash. This was addressed in epan/dissectors/packet-sigcomp.c by correcting the extraction of the length value.
External References:
https://www.wireshark.org/security/wnpa-sec-2018-13.html
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14410
Upstream Patch:
https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=29d920b8309905
Discussion:
Created wireshark tracking bugs for this issue:
Affects: fedora-all [bug 1549306]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1047 https://access.redhat.com/errata/RHSA-2020:1047
---
This bug is now closed.
2020-10-16
Published