CVE-2020-1232Out-of-bounds Read in Microsoft Windows

Severity
6.5MEDIUMNVD
EPSS
24.5%
top 3.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 9
Latest updateMar 14

Description

An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory, aka 'Media Foundation Information Disclosure Vulnerability'.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages13 packages

CVEListV5microsoft/windows11 versions+10
NVDmicrosoft/windows4 versions+3
NVDmicrosoft/windows_107 versions+6
CVEListV5microsoft/windows_server5 versions+4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-gjjq-hmq3-g2h6: An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory, aka 'Media Foundation Information Disclosur2022-05-24
CVEList
CVE-2020-1232: An information disclosure vulnerability exists when Media Foundation improperly handles objects in memory, aka 'Media Foundation Information Disclosur2020-06-09

📋Vendor Advisories

2
Microsoft
An issue was discovered in Dnsmasq before 2.90. The default maximum EDNS.0 UDP packet size was set to 4096 but should be 1232 because of DNS Flag Day 2020.2023-03-14
Microsoft
Media Foundation Information Disclosure Vulnerability2020-06-09
CVE-2020-1232 — Out-of-bounds Read in Microsoft Windows | cvebase