CVE-2020-1267Improper Input Validation in Microsoft Windows

Severity
4.9MEDIUMNVD
EPSS
3.4%
top 12.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 14
Latest updateMay 24

Description

This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when an authenticated attacker sends a specially crafted authentication request, aka 'Local Security Authority Subsystem Service Denial of Service Vulnerability'.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 1.2 | Impact: 3.6

Affected Packages13 packages

CVEListV5microsoft/windows18 versions+17
NVDmicrosoft/windows4 versions+3
NVDmicrosoft/windows_107 versions+6
CVEListV5microsoft/windows_server14 versions+13

Patches

🔴Vulnerability Details

2
GHSA
GHSA-f6v8-7355-p32v: This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when an authenticated attacker send2022-05-24
CVEList
CVE-2020-1267: This security update corrects a denial of service in the Local Security Authority Subsystem Service (LSASS) caused when an authenticated attacker send2020-07-14

📋Vendor Advisories

1
Microsoft
Local Security Authority Subsystem Service Denial of Service Vulnerability2020-07-14
CVE-2020-1267 — Improper Input Validation in Microsoft | cvebase