cbcvebase.
CVE-2020-1286
published 2020-06-09

CVE-2020-1286: A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.An attacker who successfully exploited this…

PriorityP355high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
11.78%
95.6th percentile
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the current user, aka 'Windows Shell Remote Code Execution Vulnerability'.

Affected

41 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10_version_1903_for_32-bit_systems
microsoftwindows_10_version_1903_for_arm64-based_systems
microsoftwindows_10_version_1903_for_x64-based_systems
microsoftwindows_10_version_1909_for_32-bit_systems
microsoftwindows_10_version_1909_for_arm64-based_systems
microsoftwindows_10_version_1909_for_x64-based_systems
microsoftwindows_10_version_2004_for_32-bit_systems
microsoftwindows_10_version_2004_for_arm64-based_systems
microsoftwindows_10_version_2004_for_x64-based_systems
microsoftwindows_server
microsoftwindows_server

Detection & IOCsextracted from sources · hover to see the quote

  • Trigger vector is a specially crafted file that must be opened by the user — monitor for suspicious file open events (email attachments or browser downloads) leading to shell process execution
  • Web-based delivery vector: attacker-hosted or compromised website serves a specially crafted file — monitor web traffic and file downloads that subsequently invoke Windows Shell (explorer.exe / shell32.dll) path validation
  • Root cause is improper file-path validation in Windows Shell — consider monitoring for anomalous child processes spawned from Windows Shell (explorer.exe) or unusual path strings passed to shell APIs
  • ·Exploitation status at time of patching was 'Exploitation Less Likely' for both latest and older software releases, and no public exploit or in-the-wild exploitation was confirmed — lower immediate priority but still a valid RCE surface
  • ·Exploitation requires user interaction (opening a crafted file); fully unattended/zero-click exploitation is not described — detection focus should include user-interaction telemetry (file open, click events)

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc7.8HIGH
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.