CVE-2020-1167: Microsoft Graphics Components Remote Code Execution Vulnerability

Overview

Severity
High (CVSS 7.8)
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
Category
Remote Code Execution
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2020-Oct
Released
2020-10-13
EPSS Score
10.59% (percentile: 93.3%)

Description

A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a user would have to open a specially crafted file. The security update addresses the vulnerability by correcting how Microsoft Graphics Components handle objects in memory.

Affected Products (24)

Other

  • 11497
  • 11498
  • 11563
  • 11568
  • 11569
  • 11570
  • 11571
  • 11712
  • 11713
  • 11714
  • 11453
  • 11454
  • 11583
  • 11644
  • 11645
  • 11646
  • 11766
  • 11767
  • 11768
  • 10729
  • 10735
  • 10852
  • 10853
  • 10816

Security Updates (8)

Acknowledgments

rgod working with <a href="https://www.zerodayinitiative.com/">Trend Micro's Zero Day Initiative</a>

Revision History

  • 2020-10-13: Information published.