CVE-2020-1267 — Improper Input Validation in Microsoft Windows
Severity
4.9MEDIUMNVD
EPSS
3.4%
top 12.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 14
Latest updateMay 24
Description
This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when an authenticated attacker sends a specially crafted authentication request, aka 'Local Security Authority Subsystem Service Denial of Service Vulnerability'.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 1.2 | Impact: 3.6
Affected Packages13 packages
Patches
🔴Vulnerability Details
2GHSA▶
GHSA-f6v8-7355-p32v: This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when an authenticated attacker send↗2022-05-24
CVEList▶
CVE-2020-1267: This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when an authenticated attacker send↗2020-07-14