CVE-2020-1429

Severity
7.8HIGH
EPSS
0.4%
top 41.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 14
Latest updateMay 24

Description

An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles a process crash, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages13 packages

CVEListV5microsoft/windows13 versions+12
NVDmicrosoft/windows1903, 1909, 2004+2
NVDmicrosoft/windows_107 versions+6
CVEListV5microsoft/windows_server4 versions+3

Patches

🔴Vulnerability Details

4
GHSA
GHSA-xf3x-83h2-c6pg: An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles a process crash, aka 'Windows Error Reporting M2022-05-24
CVEList
CVE-2020-1429: An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles a process crash, aka 'Windows Error Reporting M2020-07-14
Project0
Project Zero RCA: CVE-2020-0674: Internet Explorer use-after-free in JScript
Project0
Project Zero RCA: CVE-2019-1367: Internet Explorer JScript use-after-free

📋Vendor Advisories

1
Microsoft
Windows Error Reporting Manager Elevation of Privilege Vulnerability2020-07-14
CVE-2020-1429 (HIGH CVSS 7.8) | An elevation of privilege vulnerabi | cvebase.io