CVE-2020-1116Sensitive Information Exposure in Microsoft Windows

Severity
5.5MEDIUMNVD
EPSS
0.4%
top 36.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 21
Latest updateMay 24

Description

An information disclosure vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects in memory, aka 'Windows CSRSS Information Disclosure Vulnerability'.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages10 packages

CVEListV5microsoft/windows_server17 versions+16
CVEListV5microsoft/windows18 versions+17
NVDmicrosoft/windows4 versions+3
NVDmicrosoft/windows_106 versions+5

Patches

🔴Vulnerability Details

2
GHSA
GHSA-jpvx-fgp9-vfvc: An information disclosure vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects in memory, a2022-05-24
CVEList
CVE-2020-1116: An information disclosure vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to properly handle objects in memory, a2020-05-21

📋Vendor Advisories

2
Microsoft
Windows CSRSS Information Disclosure Vulnerability2020-05-12
Red Hat
ncurses: Stack buffer overflow in fmt_entry function in progs/dump_entry.c:11162019-05-03

💬Community

1
Bugzilla
CVE-2018-1116 polkit: Improper authorization in polkit_backend_interactive_authority_check_authorization function in polkitd2018-06-26
CVE-2020-1116 — Sensitive Information Exposure | cvebase