CVE-2020-1159
published 2020-09-11CVE-2020-1159: An elevation of privilege vulnerability exists in the way that the StartTileData.dll handles file creation in protected locations. An attacker who successfully…
PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.72%
50.2th percentile
An elevation of privilege vulnerability exists in the way that the StartTileData.dll handles file creation in protected locations. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.
The security update addresses the vulnerability by ensuring the StartTileData.dll properly handles this type of function.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1903_for_32-bit_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_arm64-based_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_x64-based_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1909 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_2004 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_version_2004 | >= 10.0.0 < publication | publication |
| msrc | windows_10_version_1903_for_32-bit_systems | — | — |
| msrc | windows_10_version_1903_for_arm64-based_systems | — | — |
| msrc | windows_10_version_1903_for_x64-based_systems | — | — |
| msrc | windows_10_version_1909_for_32-bit_systems | — | — |
| msrc | windows_10_version_1909_for_arm64-based_systems | — | — |
| msrc | windows_10_version_1909_for_x64-based_systems | — | — |
| msrc | windows_10_version_2004_for_32-bit_systems | — | — |
| msrc | windows_10_version_2004_for_arm64-based_systems | — | — |
| msrc | windows_10_version_2004_for_x64-based_systems | — | — |
| msrc | windows_server_version_1903 | — | — |
| msrc | windows_server_version_1909 | — | — |
| msrc | windows_server_version_2004 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_msrc5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mh84-f3mw-wvjc: An elevation of privilege vulnerability exists in the way that the ssdpsrv
ghsa_unreviewed·2022-05-24·CVSS 6.6
CVE-2020-1052 [MEDIUM] CWE-269 GHSA-mh84-f3mw-wvjc: An elevation of privilege vulnerability exists in the way that the ssdpsrv
An elevation of privilege vulnerability exists in the way that the ssdpsrv.dll handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1159, CVE-2020-1376.
GHSA
GHSA-jq5x-rvwv-2mcf: An elevation of privilege vulnerability exists in the way that fdSSDP
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-1376 [HIGH] CWE-269 GHSA-jq5x-rvwv-2mcf: An elevation of privilege vulnerability exists in the way that fdSSDP
An elevation of privilege vulnerability exists in the way that fdSSDP.dll handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1052, CVE-2020-1159.
GHSA
GHSA-954v-jx2j-mhwf: An elevation of privilege vulnerability exists in the way that the StartTileData
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-1159 [HIGH] CWE-269 GHSA-954v-jx2j-mhwf: An elevation of privilege vulnerability exists in the way that the StartTileData
An elevation of privilege vulnerability exists in the way that the StartTileData.dll handles file creation in protected locations, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1052, CVE-2020-1376.
Microsoft
Windows Elevation of Privilege Vulnerability
vendor_msrc·2020-09-08·CVSS 5.3
CVE-2020-1159 [MEDIUM] Windows Elevation of Privilege Vulnerability
Windows Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in the way that the StartTileData.dll handles file creation in protected locations. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.
The security update addresses the vulnerability by ensuring the StartTileData.dll properly handles this type of function.
Microsoft Windows: Microsoft Windows
Microsoft: Microsoft
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.up
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Multiple vulnerabilities in Synology DiskStation Manager
blogs_talos·2021-04-20·CVSS 9.0
CVE-2021-26564 [CRITICAL] Vulnerability Spotlight: Multiple vulnerabilities in Synology DiskStation Manager
## Vulnerability Spotlight: Multiple vulnerabilities in Synology DiskStation Manager
Cisco Talos recently discovered multiple vulnerabilities in Synology DiskStation Manager.
DSM is the Linux-based operating system for every Synology network-attached storage device (NAS). The vulnerabilities exist in various features inside the operating system, including AppArmor and QuickConnect. TALOS-2020-1173 and TALOS-2020-1160 (CVE-2021-26564, CVE-2021-26565 and CVE-2021-26566) are both information disclosure vulnerabilities in DSM. An attacker could exploit both vulnerabilities to steal sensitive login credentials, including those of an administrator.
An attacker could also exploit TALOS-2020-1159 (CVE-2021-26560, CVE-2021-26561 and CVE-2021-26562) with a man-in-the-middle technique to gain the
Talos
Vulnerability Spotlight: Multiple vulnerabilities in Synology DiskStation Manager
blogs_talos·2021-04-20·CVSS 9.0
CVE-2021-26564 [CRITICAL] Vulnerability Spotlight: Multiple vulnerabilities in Synology DiskStation Manager
Cisco Talos recently discovered multiple vulnerabilities in Synology DiskStation Manager.
DSM is the Linux-based operating system for every Synology network-attached storage device (NAS). The vulnerabilities exist in various features inside the operating system, including AppArmor and QuickConnect. TALOS-2020-1173 and TALOS-2020-1160 (CVE-2021-26564, CVE-2021-26565 and CVE-2021-26566) are both information disclosure vulnerabilities in DSM. An attacker could exploit both vulnerabilities to steal sensitive login credentials, including those of an administrator.
An attacker could also exploit TALOS-2020-1159 (CVE-2021-26560, CVE-2021-26561 and CVE-2021-26562) with a man-in-the-middle technique to gain the ability to remotely execute code as the root user (however within a restricted AppArmo
2020-09-11
Published