CVE-2020-1441: Windows Spatial Data Service Elevation of Privilege Vulnerability

Overview

Severity
High (CVSS 7)
CVSS Vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
Category
Elevation of Privilege
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2020-Jun
Released
2020-06-17

Description

An elevation of privilege vulnerability exists when the Windows Spatial Data Service improperly handles objects in memory. An attacker could exploit the vulnerability to overwrite or modify a protected file leading to a privilege escalation. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application. The security update addresses the vulnerability by addressing how the Windows Spatial Data Service handles objects in memory.

Affected Products (2)

Windows

  • Windows 10 Version 1903 for 32-bit Systems
  • Windows 10 Version 1903 for x64-based Systems

Security Updates (1)

Acknowledgments

Jarvis_1oop of Pinduoduo Security Research Lab, Zhiniang Peng (<a href="https://twitter.com/edwardzpeng">@edwardzpeng</a>) & Haoran Qin (<a href="https://twitter.com/Q4n">@Q4n</a>)

Revision History

  • 2020-06-17: Information published.