CVE-2020-1286
published 2020-06-09CVE-2020-1286: A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.An attacker who successfully exploited this…
PriorityP355high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
11.78%
95.6th percentile
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the current user, aka 'Windows Shell Remote Code Execution Vulnerability'.
Affected
41 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1903_for_32-bit_systems | — | — |
| microsoft | windows_10_version_1903_for_arm64-based_systems | — | — |
| microsoft | windows_10_version_1903_for_x64-based_systems | — | — |
| microsoft | windows_10_version_1909_for_32-bit_systems | — | — |
| microsoft | windows_10_version_1909_for_arm64-based_systems | — | — |
| microsoft | windows_10_version_1909_for_x64-based_systems | — | — |
| microsoft | windows_10_version_2004_for_32-bit_systems | — | — |
| microsoft | windows_10_version_2004_for_arm64-based_systems | — | — |
| microsoft | windows_10_version_2004_for_x64-based_systems | — | — |
| microsoft | windows_server | — | — |
| microsoft | windows_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Trigger vector is a specially crafted file that must be opened by the user — monitor for suspicious file open events (email attachments or browser downloads) leading to shell process execution ↗
- →Web-based delivery vector: attacker-hosted or compromised website serves a specially crafted file — monitor web traffic and file downloads that subsequently invoke Windows Shell (explorer.exe / shell32.dll) path validation ↗
- →Root cause is improper file-path validation in Windows Shell — consider monitoring for anomalous child processes spawned from Windows Shell (explorer.exe) or unusual path strings passed to shell APIs ↗
- ·Exploitation status at time of patching was 'Exploitation Less Likely' for both latest and older software releases, and no public exploit or in-the-wild exploitation was confirmed — lower immediate priority but still a valid RCE surface ↗
- ·Exploitation requires user interaction (opening a crafted file); fully unattended/zero-click exploitation is not described — detection focus should include user-interaction telemetry (file open, click events) ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc7.8HIGH
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-57wr-v5x3-8qhf: A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths
ghsa_unreviewed·2022-05-24
CVE-2020-1286 [HIGH] GHSA-57wr-v5x3-8qhf: A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the current user, aka 'Windows Shell Remote Code Execution Vulnerability'.
Red Hat
nodejs-url-parse: mishandling certain uses of backslash may lead to confidentiality compromise
vendor_redhat·2021-02-22·CVSS 5.3
CVE-2021-27515 [MEDIUM] CWE-1286 nodejs-url-parse: mishandling certain uses of backslash may lead to confidentiality compromise
nodejs-url-parse: mishandling certain uses of backslash may lead to confidentiality compromise
url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.
An input validation flaw exists in the node.js-url-parse, which results in the URL being incorrectly set to the document location protocol instead of the URL being passed as an argument. This flaw allows an attacker to bypass security checks on URLs. The highest threat from this vulnerability is to integrity. This is an incomplete fix for CVE-2020-8124.
Package: servicemesh-grafana (OpenShift Service Mesh 2.0) - Not affected
Package: servicemesh-prometheus (OpenShift Service Mesh 2.0) - Not affected
Package: rhacm2/console-rhel8 (Red Hat Advanced Cluster Management for Kuber
Microsoft
Windows Shell Remote Code Execution Vulnerability
vendor_msrc·2020-06-09·CVSS 7.8
CVE-2020-1286 [HIGH] Windows Shell Remote Code Execution Vulnerability
Windows Shell Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.
An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the current user. If the current user is logged on as an administrator, an attacker could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with elevated privileges. Users whose accounts are configured to have fewer privileges on the system could be less impacted than users who operate with administrative privileges.
To exploit the vulnerability, an attacker must entice a user to open a specially crafted file. In an email attack scenario, an a
No detection rules found.
No public exploits indexed.
2020-06-09
Published