CVE-2020-1485Sensitive Information Exposure in Microsoft Windows 10 Version 1507

Severity
5.5MEDIUMNVD
EPSS
0.4%
top 40.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 17
Latest updateMay 24

Description

An information disclosure vulnerability exists when the Windows Image Acquisition (WIA) Service improperly discloses contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. To exploit the vulnerability, an authenticated attacker could connect an imaging device (camera, scanner, cellular phone) to an affected system and run a specially crafted application to disclose information. The security update address

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages23 packages

CVEListV5microsoft/windows_7_service_pack_16.1.0publication
CVEListV5microsoft/windows_server_2008_service_pack_26.0.0publication
CVEListV5microsoft/windows_server_2008_r2_service_pack_16.1.0publication+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-7rr2-mfr6-x27q: An information disclosure vulnerability exists when the Windows Image Acquisition (WIA) Service improperly discloses contents of its memory, aka 'Wind2022-05-24
CVEList
Windows Image Acquisition Service Information Disclosure Vulnerability2020-08-17

📋Vendor Advisories

1
Microsoft
Windows Image Acquisition Service Information Disclosure Vulnerability2020-08-11
CVE-2020-1485 — Sensitive Information Exposure | cvebase