CVE-2020-1259Insufficiently Protected Credentials in Microsoft Windows

Severity
4.3MEDIUMNVD
EPSS
6.7%
top 8.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 9
Latest updateMay 24

Description

A security feature bypass vulnerability exists when Windows Host Guardian Service improperly handles hashes recorded and logged, aka 'Windows Host Guardian Service Security Feature Bypass Vulnerability'.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages13 packages

CVEListV5microsoft/windows13 versions+12
NVDmicrosoft/windows4 versions+3
NVDmicrosoft/windows_106 versions+5
CVEListV5microsoft/windows_server5 versions+4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4538-wpvw-289w: A security feature bypass vulnerability exists when Windows Host Guardian Service improperly handles hashes recorded and logged, aka 'Windows Host Gua2022-05-24
CVEList
CVE-2020-1259: A security feature bypass vulnerability exists when Windows Host Guardian Service improperly handles hashes recorded and logged, aka 'Windows Host Gua2020-06-09

📋Vendor Advisories

1
Microsoft
Windows Host Guardian Service Security Feature Bypass Vulnerability2020-06-09
CVE-2020-1259 — Insufficiently Protected Credentials | cvebase