CVE-2020-1270
published 2020-06-09CVE-2020-1270: An elevation of privilege vulnerability exists in the way that the wlansvc.dll handles objects in memory, aka 'Windows WLAN Service Elevation of Privilege…
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.76%
51.6th percentile
An elevation of privilege vulnerability exists in the way that the wlansvc.dll handles objects in memory, aka 'Windows WLAN Service Elevation of Privilege Vulnerability'.
Affected
74 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qp79-x3vg-c795: An elevation of privilege vulnerability exists in the way that the wlansvc
ghsa_unreviewed·2022-05-24
CVE-2020-1270 [MEDIUM] CWE-269 GHSA-qp79-x3vg-c795: An elevation of privilege vulnerability exists in the way that the wlansvc
An elevation of privilege vulnerability exists in the way that the wlansvc.dll handles objects in memory, aka 'Windows WLAN Service Elevation of Privilege Vulnerability'.
Microsoft
Windows WLAN Service Elevation of Privilege Vulnerability
vendor_msrc·2020-06-09·CVSS 7.8
CVE-2020-1270 [HIGH] Windows WLAN Service Elevation of Privilege Vulnerability
Windows WLAN Service Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in the way that the wlansvc.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.
The security update addresses the vulnerability by ensuring the wlansvc.dll properly handles objects in memory.
Microsoft Windows: Microsoft Windows
Microsoft: Microsoft
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-6427 chromium-browser: Use after free in audio
bugzilla·2020-03-19·CVSS 8.8
CVE-2020-6427 [HIGH] CVE-2020-6427 chromium-browser: Use after free in audio
CVE-2020-6427 chromium-browser: Use after free in audio
An use after free flaw was found in the audio component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1055788
External References:
https://chromereleases.googleblog.com/2020/03/stable-channel-update-for-desktop_18.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1815255]
Affects: fedora-all [bug 1815253]
---
FEDORA-2020-17149a4f3d has been pushed to the Fedora 32 stable repository.
If problem still persists, please make note of it in this bug report.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1270 https://access.redhat.com/errata/RHSA-2020:1270
---
This bug is no
Bugzilla
CVE-2020-6449 chromium-browser: Use after free in audio
bugzilla·2020-03-19·CVSS 8.8
CVE-2020-6449 [HIGH] CVE-2020-6449 chromium-browser: Use after free in audio
CVE-2020-6449 chromium-browser: Use after free in audio
An use after free flaw was found in the audio component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1059686
External References:
https://chromereleases.googleblog.com/2020/03/stable-channel-update-for-desktop_18.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1815255]
Affects: fedora-all [bug 1815253]
---
FEDORA-2020-17149a4f3d has been pushed to the Fedora 32 stable repository.
If problem still persists, please make note of it in this bug report.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1270 https://access.redhat.com/errata/RHSA-2020:1270
---
This bug is no
Bugzilla
CVE-2020-6429 chromium-browser: Use after free in audio
bugzilla·2020-03-19·CVSS 8.8
CVE-2020-6429 [HIGH] CVE-2020-6429 chromium-browser: Use after free in audio
CVE-2020-6429 chromium-browser: Use after free in audio
An use after free flaw was found in the audio component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1057627
External References:
https://chromereleases.googleblog.com/2020/03/stable-channel-update-for-desktop_18.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1815255]
Affects: fedora-all [bug 1815253]
---
FEDORA-2020-17149a4f3d has been pushed to the Fedora 32 stable repository.
If problem still persists, please make note of it in this bug report.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1270 https://access.redhat.com/errata/RHSA-2020:1270
---
This bug is no
Bugzilla
CVE-2020-6424 chromium-browser: Use after free in media
bugzilla·2020-03-19·CVSS 8.8
CVE-2020-6424 [HIGH] CVE-2020-6424 chromium-browser: Use after free in media
CVE-2020-6424 chromium-browser: Use after free in media
An use after free flaw was found in the media component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1031142
External References:
https://chromereleases.googleblog.com/2020/03/stable-channel-update-for-desktop_18.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1815255]
Affects: fedora-all [bug 1815253]
---
FEDORA-2020-17149a4f3d has been pushed to the Fedora 32 stable repository.
If problem still persists, please make note of it in this bug report.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1270 https://access.redhat.com/errata/RHSA-2020:1270
---
This bug is no
Bugzilla
CVE-2020-6426 chromium-browser: Inappropriate implementation in V8
bugzilla·2020-03-19·CVSS 6.5
CVE-2020-6426 [MEDIUM] CVE-2020-6426 chromium-browser: Inappropriate implementation in V8
CVE-2020-6426 chromium-browser: Inappropriate implementation in V8
An inappropriate implementation flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1052647
External References:
https://chromereleases.googleblog.com/2020/03/stable-channel-update-for-desktop_18.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1815255]
Affects: fedora-all [bug 1815253]
---
FEDORA-2020-17149a4f3d has been pushed to the Fedora 32 stable repository.
If problem still persists, please make note of it in this bug report.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1270 https://access.redhat.com/errata/RHSA-2020:127
Bugzilla
CVE-2020-6422 chromium-browser: Use after free in WebGL
bugzilla·2020-03-19·CVSS 8.8
CVE-2020-6422 [HIGH] CVE-2020-6422 chromium-browser: Use after free in WebGL
CVE-2020-6422 chromium-browser: Use after free in WebGL
An use after free flaw was found in the WebGL component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1051748
External References:
https://chromereleases.googleblog.com/2020/03/stable-channel-update-for-desktop_18.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1815265]
Affects: fedora-all [bug 1815264]
---
FEDORA-2020-17149a4f3d has been pushed to the Fedora 32 stable repository.
If problem still persists, please make note of it in this bug report.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1270 https://access.redhat.com/errata/RHSA-2020:1270
---
This bug is no
Bugzilla
CVE-2020-6425 chromium-browser: Insufficient policy enforcement in extensions
bugzilla·2020-03-19·CVSS 5.4
CVE-2020-6425 [MEDIUM] CVE-2020-6425 chromium-browser: Insufficient policy enforcement in extensions
CVE-2020-6425 chromium-browser: Insufficient policy enforcement in extensions
An insufficient policy enforcement flaw was found in the extensions component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1031670
External References:
https://chromereleases.googleblog.com/2020/03/stable-channel-update-for-desktop_18.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1815255]
Affects: fedora-all [bug 1815253]
---
FEDORA-2020-17149a4f3d has been pushed to the Fedora 32 stable repository.
If problem still persists, please make note of it in this bug report.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1270 https://access.redhat.co
Bugzilla
CVE-2020-6428 chromium-browser: Use after free in audio
bugzilla·2020-03-19·CVSS 8.8
CVE-2020-6428 [HIGH] CVE-2020-6428 chromium-browser: Use after free in audio
CVE-2020-6428 chromium-browser: Use after free in audio
An use after free flaw was found in the audio component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1057593
External References:
https://chromereleases.googleblog.com/2020/03/stable-channel-update-for-desktop_18.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1815255]
Affects: fedora-all [bug 1815253]
---
FEDORA-2020-17149a4f3d has been pushed to the Fedora 32 stable repository.
If problem still persists, please make note of it in this bug report.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:1270 https://access.redhat.com/errata/RHSA-2020:1270
---
This bug is no
2020-06-09
Published