CVE-2020-17087
published 2020-11-11CVE-2020-17087: Windows Kernel Local Elevation of Privilege Vulnerability
PriorityP180high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
5.39%
91.8th percentile
Windows Kernel Local Elevation of Privilege Vulnerability
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_version_1507 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1607 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1803 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1809 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_32-bit_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_arm64-based_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_x64-based_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1909 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_2004 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < publication | publication |
| microsoft | windows_7 | >= 6.1.0 < publication | publication |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < publication | publication |
| microsoft | windows_8.1 | >= 6.3.0 < publication | publication |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.0.0 < publication | publication |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.0 < publication | publication |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.0 < publication | publication |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.0 < publication | publication |
| microsoft | windows_server_2012_r2 | >= 6.3.0 < publication | publication |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | >= 10.0.0 < publication | publication |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for user-mode applications sending IOCTLs to the \Device\CNG (DeviceCNG) device exposed by cng.sys; exploitation of CVE-2020-17087 occurs within a specific IOCTL path inside this driver. ↗
- →CVE-2020-17087 is chained with CVE-2020-15999 (Chrome Freetype heap buffer overflow); detect Chrome renderer processes spawning unexpected privileged child processes or making unusual kernel driver calls as a sign of sandbox escape. ↗
- →Enable Additional User-Mode Data (AUMD) in endpoint prevention policies to gain detection visibility of user-mode IOCTL interactions with vulnerable kernel device drivers such as cng.sys. ↗
- →Post-exploitation: alert on execution of nltest, setspn, net group /domain, net localgroup, net use, and net share from non-administrative or browser-sandboxed processes, as these are used for reconnaissance after privilege escalation. ↗
- →Check Point IPS signature name for CVE-2020-17087 is 'Microsoft Windows Kernel Local Elevation of Privilege (CVE-2020-17087)'; use this signature string for IPS rule cross-referencing. ↗
- ·The vulnerability affects Windows 7 through Windows 10, meaning detection and patching scope must cover the full range of these OS versions. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.6CRITICAL
cisa9.6CRITICAL
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-frqf-hcmw-8jjf: Windows Kernel Local Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2020-17087 [HIGH] CWE-131 GHSA-frqf-hcmw-8jjf: Windows Kernel Local Elevation of Privilege Vulnerability
Windows Kernel Local Elevation of Privilege Vulnerability
Project0
In-the-Wild Series: October 2020 0-day discovery - Project Zero
project_zero·2021-03-01·CVSS 9.6
CVE-2020-15999 [CRITICAL] In-the-Wild Series: October 2020 0-day discovery - Project Zero
Posted by Maddie Stone, Project Zero
In October 2020, Google Project Zero discovered seven 0-day exploits being actively used in-the-wild. These exploits were delivered via "watering hole" attacks in a handful of websites pointing to two exploit servers that hosted exploit chains for Android, Windows, and iOS devices. These attacks appear to be the next iteration of the campaign discovered in February 2020 and documented in this blog post series.
In this post we are summarizing the exploit chains we discovered in October 2020. We have already published the details of the seven 0-day vulnerabilities exploited in our root cause analysis (RCA) posts. This post aims to provide the context around these exploits.What happened
In October 2020, we discovered that the actor from the Feb
VulnCheck
Microsoft Windows Kernel Privilege Escalation Vulnerability
vulncheck·2020·CVSS 8.8
CVE-2020-17087 [HIGH] CWE-131 Microsoft Windows Kernel Privilege Escalation Vulnerability
Microsoft Windows Kernel Privilege Escalation Vulnerability
Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.
Affected: Microsoft Windows
Required Action: Apply updates per vendor instructions.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2020-Nov; https://googleprojectzero.github.io/0days-in-the-wild//0day-RCAs/2020/CVE-2020-16009.html; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Exploit PoC: https://vulncheck.com/xdb/7eed0e9442ec; https://vulncheck.com/xdb/8fe698ce7fbd
Remediation Due: 2022-05-03
VulnCheck
Google Chrome FreeType Heap Buffer Overflow Vulnerability
vulncheck·2020·CVSS 9.6
CVE-2020-15999 [CRITICAL] CWE-787 Google Chrome FreeType Heap Buffer Overflow Vulnerability
Google Chrome FreeType Heap Buffer Overflow Vulnerability
Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android.
Affected: Google Chrome FreeType
Required Action: Apply updates per vendor instructions.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://savannah.nongnu.org/bugs/?59308; https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html; https://googleprojectzero.github.io/0days-in-the-wild//0day-RCAs/2020/CVE-2020-16009.ht
Project0
Project Zero RCA: CVE-2020-16009: Chrome Turbofan Type Confusion after Map Deprecation
project_zero·CVSS 8.8
CVE-2020-16009 [HIGH] Project Zero RCA: CVE-2020-16009: Chrome Turbofan Type Confusion after Map Deprecation
# CVE-2020-16009: Chrome Turbofan Type Confusion after Map Deprecation
*Samuel Groß, Project Zero (Originally posted on [Project Zero blog](https://googleprojectzero.blogspot.com/p/rca.html) 2021-02-04)*
## The Basics
**Disclosure or Patch Date:** 2 November 2020
**Product:** Google Chrome
**Advisory:** https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop.html
**Affected Versions:** 86.0.4240.111 and previous
**First Patched Version:** 86.0.4240.183
**Issue/Bug Report:**
* Project Zero: https://bugs.chromium.org/p/project-zero/issues/detail?id=2106
* Chromium: https://bugs.chromium.org/p/chromium/issues/detail?id=1143772
**Patch CL:** https://chromium.googlesource.com/v8/v8.git/+/3ba21a17ce2f26b015cc29adc473812247472776
**Bug-Introducing CL:** N/A
**Re
Project0
Project Zero RCA: CVE-2020-17087: Windows pool buffer overflow in cng.sys IOCTL
project_zero·CVSS 7.8
CVE-2020-17087 [HIGH] Project Zero RCA: CVE-2020-17087: Windows pool buffer overflow in cng.sys IOCTL
# CVE-2020-17087: Windows pool buffer overflow in cng.sys IOCTL
*Mateusz Jurczyk, Project Zero (Originally posted on [Project Zero blog](https://googleprojectzero.blogspot.com/p/rca.html) 2021-02-04)*
## The Basics
**Disclosure or Patch Date:**
* Disclosure: 30 October 2020 by Google Project Zero
* Patch Date: 10 November 2020
**Product:** Microsoft Windows
**Advisory:** https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2020-17087
**Affected Versions:** For Windows 10 2004, [KB4579311](https://support.microsoft.com/en-us/help/4579311) and previous
**First Patched Version:** For Windows 10 2004, [KB4586781](https://support.microsoft.com/en-us/help/4586781/windows-10-update-kb4586781)
**Issue/Bug Report:** https://bugs.chromium.org/p/project-zero/issues/detail?id=2104
Project0
Project Zero RCA: CVE-2020-15999: FreeType Heap Buffer Overflow in Load_SBit_Png
project_zero·CVSS 9.6
CVE-2020-15999 [CRITICAL] Project Zero RCA: CVE-2020-15999: FreeType Heap Buffer Overflow in Load_SBit_Png
# CVE-2020-15999: FreeType Heap Buffer Overflow in Load_SBit_Png
*Sergei Glazunov, Project Zero (Originally posted on [Project Zero blog](https://googleprojectzero.blogspot.com/p/rca.html) 2021-02-04)*
## The Basics
**Disclosure or Patch Date:** 19 October 2020
**Product:** Google Chrome/ Freetype
**Advisory:** https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html
**Affected Versions:** 86.0.4240.80 and previous
**First Patched Version:** 86.0.4240.111
**Issue/Bug Report:**
* Project Zero: https://bugs.chromium.org/p/project-zero/issues/detail?id=2103
* Chromium: https://bugs.chromium.org/p/chromium/issues/detail?id=1139963
* FreeType: https://savannah.nongnu.org/bugs/?59308
**Patch CL:**
* Chromium: https://chromium.googlesource.com/chromium/src
CISA
Microsoft Windows Kernel Privilege Escalation Vulnerability
cisa·2021-11-03·CVSS 7.8
CVE-2020-17087 [HIGH] CWE-131 Microsoft Windows Kernel Privilege Escalation Vulnerability
Vulnerability: Microsoft Windows Kernel Privilege Escalation Vulnerability
Affected: Microsoft Windows
Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-17087
Remediation Due Date: 2022-05-03
CISA
Google Chrome FreeType Heap Buffer Overflow Vulnerability
cisa·2021-11-03·CVSS 9.6
CVE-2020-15999 [CRITICAL] CWE-787 Google Chrome FreeType Heap Buffer Overflow Vulnerability
Vulnerability: Google Chrome FreeType Heap Buffer Overflow Vulnerability
Affected: Google Chrome FreeType
Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-15999
Remediation Due Date: 2021-11-17
Microsoft
Windows Kernel Local Elevation of Privilege Vulnerability
vendor_msrc·2020-11-10·CVSS 7.8
CVE-2020-17087 [HIGH] Windows Kernel Local Elevation of Privilege Vulnerability
Windows Kernel Local Elevation of Privilege Vulnerability
Windows Kernel: Windows Kernel
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:Yes;Exploited:Yes;Latest Software Release:Exploitation Detected;Older Software Release:Exploitation Detected;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4586785
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4586793
Reference: https://support.microsoft.com/help/4586793
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4586786
Reference: https://support.microsoft.com/help/4586786
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4586781
Reference: https://support.microsoft.
No detection rules found.
No public exploits indexed.
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
blogs_qualys·2022-02-23
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
#### Table of Contents
- Situation
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISA Vulnerabilities Using Qualys VMDR
- CISA Exploited RTI
- Detailed Operational Dashboard
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
CISA released a directive in November 2021, recommending urgent and prioritized remediation of actively exploited vulnerabilities. Both government agencies and corporations should heed this advice. This blog outlines how Qualys Vulnerability Management, Detection & Response can be used by any organization to respond to this directive efficiently and effectively.
## Situation
Last November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directiv
Qualys
January 2021 Patch Tuesday – 83 Vulnerabilities, 10 Critical, One Zero Day, Adobe | Qualys
blogs_qualys·2021-01-12·CVSS 7.8
[HIGH] January 2021 Patch Tuesday – 83 Vulnerabilities, 10 Critical, One Zero Day, Adobe | Qualys
This month’s Microsoft Patch Tuesday addresses 83 vulnerabilities. The 10 Critical vulnerabilities cover Windows codecs, Office, HEVC video extensions, RPC runtime, and several other workstation vulnerabilities. Adobe released patches today for Photoshop, Campaign Classic, InCopy, Illustrator, Captivate, Bridge and Animate.
### Workstation Patches
Office and Edge vulnerabilities should be prioritized for workstation-type devices, meaning any system that is used to access email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users.
### Microsoft Defender RCE Zero Day
Microsoft patches Defender Remote Code Execution vulnerability (CVE-2021-1647) in today’s patch release for Microsoft Malware Protection Engine. Microsoft state
Qualys
January 2021 Patch Tuesday – 83 Vulnerabilities, 10 Critical, One Zero Day, Adobe
blogs_qualys·2021-01-12·CVSS 7.8
[HIGH] January 2021 Patch Tuesday – 83 Vulnerabilities, 10 Critical, One Zero Day, Adobe
This month’s Microsoft Patch Tuesday addresses 83 vulnerabilities. The 10 Critical vulnerabilities cover Windows codecs, Office, HEVC video extensions, RPC runtime, and several other workstation vulnerabilities. Adobe released patches today for Photoshop, Campaign Classic, InCopy, Illustrator, Captivate, Bridge and Animate.
## Workstation Patches
Office and Edge vulnerabilities should be prioritized for workstation-type devices, meaning any system that is used to access email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users.
## Microsoft Defender RCE Zero Day
Microsoft patches Defender Remote Code Execution vulnerability ( CVE-2021-1647 ) in today’s patch release for Microsoft Malware Protection Engine. Microsoft state
Checkpoint
16th November – Threat Intelligence Bulletin
blogs_checkpoint·2020-11-16
CVE-2020-16013 16th November – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 16th November – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 16th November, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point Research has further investigated the newly revealed ‘Pay2Key’ ransomware, tracing several ransom payments to an Iranian cryptocurrency exchange, and concluded that the malware, which focuses on Israeli organizations, is most likely of Iranian origin.
Check Point SandBlast Agent provides protection agains
Krebs
Patch Tuesday, November 2020 Edition
blogs_krebs·2020-11-11·CVSS 9.6
[CRITICAL] Patch Tuesday, November 2020 Edition
Adobe and Microsoft each issued a bevy of updates today to plug critical security holes in their software. Microsoft’s release includes fixes for 112 separate flaws, including one zero-day vulnerability that is already being exploited to attack Windows users. Microsoft also is taking flak for changing its security advisories and limiting the amount of information disclosed about each bug.
Some 17 of the 112 issues fixed in today’s patch batch involve “critical” problems in Windows, or those that can be exploited by malware or malcontents to seize complete, remote control over a vulnerable Windows computer without any help from users.
Most of the rest were assigned the rating “important,” which in Redmond parlance refers to a vulnerability whose exploitation could “compromise the confiden
Trendmicro
November Patch Tuesday Fixes Exchange, NFS Vulns
blogs_trendmicro·2020-11-11·CVSS 9.6
[CRITICAL] November Patch Tuesday Fixes Exchange, NFS Vulns
Exploits & Vulnerabilities
# November Patch Tuesday Fixes Exchange, NFS Vulns
Comparing to last month’s update, which saw a noticeable drop to over 80 fixes, the total number of patches for this month increased again, with over a hundred patches released.
By: Trend Micro
2020/11/11
Read time: ( words)
Save to Folio
Microsoft’s Patch Tuesday for November had 112 patches, with 17 categorized as critical. Compared to last month’s update, which saw a noticeable drop to over 80 fixes, the total number of patches for this month increased again, with over a hundred patches released. Six of the vulnerabilities came through the Zero Day Initiative program. Details on the patches can be viewed on Microsoft’s Security Update Guide page.
Patch for recently disclosed zero-day CVE-2020-17087
Thi
Tenable
Microsoft’s November 2020 Patch Tuesday Addresses 112 CVEs including CVE-2020-17087
blogs_tenable·2020-11-10·CVSS 7.8
[HIGH] Microsoft’s November 2020 Patch Tuesday Addresses 112 CVEs including CVE-2020-17087
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
November 2020 Patch Tuesday – 112 Vulnerabilities, 17 Critical, Windows Codecs, Network File System, Workstation, Adobe | Qualys
blogs_qualys·2020-11-10·CVSS 5.3
[MEDIUM] November 2020 Patch Tuesday – 112 Vulnerabilities, 17 Critical, Windows Codecs, Network File System, Workstation, Adobe | Qualys
This month’s Microsoft Patch Tuesday addresses 112 vulnerabilities with 17 of them labeled as Critical. The 17 Critical vulnerabilities cover Windows Codecs, Network File System, Sharepoint, Windows Print Spooler, and several other workstation vulnerabilities. Adobe released patches today for Adobe Connect and Adobe Reader for Android.
### Workstation Patches
The Windows Codecs, GDI+, Browser, Office and Exchange Server vulnerabilities should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users.
### SharePoint RCE
Microsoft patched six vulnerabilities in SharePoint, and one of them could lead to Remote Code Execution (CVE-2020-17061). Th
Qualys
November 2020 Patch Tuesday – 112 Vulnerabilities, 17 Critical, Windows Codecs, Network File System, Workstation, Adobe
blogs_qualys·2020-11-10·CVSS 5.3
[MEDIUM] November 2020 Patch Tuesday – 112 Vulnerabilities, 17 Critical, Windows Codecs, Network File System, Workstation, Adobe
This month’s Microsoft Patch Tuesday addresses 112 vulnerabilities with 17 of them labeled as Critical. The 17 Critical vulnerabilities cover Windows Codecs, Network File System, Sharepoint, Windows Print Spooler, and several other workstation vulnerabilities. Adobe released patches today for Adobe Connect and Adobe Reader for Android.
## Workstation Patches
The Windows Codecs, GDI+, Browser, Office and Exchange Server vulnerabilities should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users.
## SharePoint RCE
Microsoft patched six vulnerabilities in SharePoint, and one of them could lead to Remote Code Execution ( CVE-2020-17061 ). Th
Krebs
Patch Tuesday, November 2020 Edition
blogs_krebs·2020-11-10·CVSS 9.6
[CRITICAL] Patch Tuesday, November 2020 Edition
Adobe and Microsoft each issued a bevy of updates today to plug critical security holes in their software. Microsoft’s release includes fixes for 112 separate flaws, including one zero-day vulnerability that is already being exploited to attack Windows users. Microsoft also is taking flak for changing its security advisories and limiting the amount of information disclosed about each bug.
Some 17 of the 112 issues fixed in today’s patch batch involve “critical” problems in Windows, or those that can be exploited by malware or malcontents to seize complete, remote control over a vulnerable Windows computer without any help from users.
Most of the rest were assigned the rating “important,” which in Redmond parlance refers to a vulnerability whose exploitation could “compromise the confiden
Sentinelone
Privilege Escalation Using CVE-2020-17087 & CVE-2020-15999
blogs_sentinelone·2020-11-04·CVSS 9.6
CVE-2020-15999 [CRITICAL] Privilege Escalation Using CVE-2020-17087 & CVE-2020-15999
A pair of zero-day vulnerabilities in Google Chrome (CVE-2020-15999) and Microsoft Windows (CVE-2020-17087) are being chained together and exploited to perform privilege escalation and gain administrator access to a system.
CVE-2020-15999 involves a type of memory-corruption vulnerability called a heap buffer overflow in Freetype, a popular open-source software development library for rendering fonts included with standard Chrome distributions.
CVE-2020-17087 involves the Windows Kernel Cryptography Driver (cng.sys) exposing a DeviceCNG device to user-mode programs and supports a variety of IOCTLs with non-trivial input structures. It constitutes a locally accessible attack surface that attackers can exploit for privilege escalation (such as sandbox escape).
Attackers can chain together
Sentinelone
Privilege Escalation Using CVE-2020-17087 & CVE-2020-15999
blogs_sentinelone·2020-11-04·CVSS 9.6
CVE-2020-17087 [CRITICAL] Privilege Escalation Using CVE-2020-17087 & CVE-2020-15999
A pair of zero-day vulnerabilities in Google Chrome (CVE-2020-15999) and Microsoft Windows (CVE-2020-17087) are being chained together and exploited to perform privilege escalation and gain administrator access to a system.
CVE-2020-15999 involves a type of memory-corruption vulnerability called a heap buffer overflow in Freetype, a popular open-source software development library for rendering fonts included with standard Chrome distributions.
CVE-2020-17087 involves the Windows Kernel Cryptography Driver (cng.sys) exposing a DeviceCNG device to user-mode programs and supports a variety of IOCTLs with non-trivial input structures. It constitutes a locally accessible attack surface that attackers can exploit for privilege escalation (such as sandbox escape).
Attackers can chain together
Checkpoint
2nd November – Threat Intelligence Bulletin
blogs_checkpoint·2020-11-02
CVE-2020-17087 2nd November – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 2nd November – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 2nd November, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
CISA, FBI and HHS have released a warning against an increase in Ryuk ransomware attacks on US hospitals. Check Point Research have shown that indeed, healthcare is currently the most targeted industry in the US, with a 71% increase in attacks compared to last month. Other regions have experienced an increase of 30%.
C
Tenable
CVE-2020-15999, CVE-2020-17087: Google Chrome FreeType and Microsoft Windows Kernel Zero Days Exploited in the Wild
blogs_tenable·2020-11-02·CVSS 9.6
[CRITICAL] CVE-2020-15999, CVE-2020-17087: Google Chrome FreeType and Microsoft Windows Kernel Zero Days Exploited in the Wild
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Sentinelone
Protecting Domain Controllers from CVE-2020-1472 ZeroLogon and Other Zero-Day Vulnerabilities
blogs_sentinelone·2020-09-16·CVSS 5.5
CVE-2020-1472 [MEDIUM] Protecting Domain Controllers from CVE-2020-1472 ZeroLogon and Other Zero-Day Vulnerabilities
Secura researchers have disclosed a vulnerability, CVE-2020-1472 Zerologon , that affects all Microsoft Windows Server versions, allowing attackers unauthenticated access to domain controllers, and has given it a CVSS score of 10.0.
They also published a technical analysis of the exploit, Proof of Concept (POC) code in a GitHub repository, that demonstrates a Netlogon authentication bypass. Essentially, the attack allows an external threat actor or malicious insider on the local network to compromise the Windows domain controller without any user authentication credentials.
The POC code requires passing the domain controller name and domain controller IP address to launch an attack.
./zerologon_tester.py EXAMPLE-DC 1.2.3.4
Attackers inside the network need to perform reconnaissance to
Crowdstrike
How to Detect and Prevent Kernel Attacks with CrowdStrike
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] How to Detect and Prevent Kernel Attacks with CrowdStrike
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Zscaler
Zscaler protects against 9 new vulnerabilities for Microsoft
blogs_zscaler·CVSS 7.0
[HIGH] Zscaler protects against 9 new vulnerabilities for Microsoft
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
CWE
Incorrect Calculation of Buffer Size
mitre_cwe
CWE-131 Incorrect Calculation of Buffer Size
CWE-131: Incorrect Calculation of Buffer Size
The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Integrity, Availability, Confidentiality. Impact: DoS: Crash, Exit, or Restart, Execute Unauthorized Code or Commands, Read Memory, Modify Memory. If the incorrect calculation is used in the context of memory allocation, then the software may create a buffer that is smaller or larger than expected. If the allocated buffer is smaller than expected, this could lead to an out-of-bounds read or write (CWE-119), possibly causing a crash, allowing arbitrary code execution, or exposing sensitive data.
Detection Methods:
Automated Static Analysis: This
CWE
Out-of-bounds Write
mitre_cwe
CWE-787 Out-of-bounds Write
CWE-787: Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Integrity. Impact: Modify Memory, Execute Unauthorized Code or Commands. Write operations could cause memory corruption. In some cases, an adversary can modify control data such as return addresses in order to execute unexpected code.
Scope: Availability. Impact: DoS: Crash, Exit, or Restart. Attempting to access out-of-range, invalid, or unauthorized memory could cause the product to crash.
Scope: Other. Impact: Unexpected State. Subsequent write operations can produce undefined or unexpected results.
Detection Methods:
Automated Static Analysis: This weakness can often be detected using automated s
CWE
Numeric Truncation Error
mitre_cwe
CWE-197 Numeric Truncation Error
CWE-197: Numeric Truncation Error
Truncation errors occur when a primitive is cast to a primitive of a smaller size and data is lost in the conversion.
When a primitive is cast to a smaller primitive, the high order bits of the large value are lost in the conversion, potentially resulting in an unexpected value that is not equal to the original value. This value may be required as an index into a buffer, a loop iterator, or simply necessary state data. In any case, the value cannot be trusted and the system will be in an undefined state. While this method may be employed viably to isolate the low bits of a value, this usage is rare, and truncation usually implies that an implementation error has occurred.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Integrit
2020-11-11
Published
2021-11-03
Added to CISA KEV
Exploited in the wild