CVE-2020-1471: Windows CloudExperienceHost Elevation of Privilege Vulnerability
Overview
- Severity
- Medium (CVSS 6.1)
- CVSS Vector
- CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N/E:P/RL:O/RC:C
- Category
- Elevation of Privilege
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2020-Sep
- Released
- 2020-09-08
- EPSS Score
- 0.68% (percentile: 71.7%)
Description
An elevation of privilege vulnerability exists when Microsoft Windows CloudExperienceHost fails to check COM objects. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system.
To exploit the vulnerability, an attacker would have to log on to an affected system and run a specially crafted script or application.
The security update addresses the vulnerability by checking COM objects.
Affected Products (24)
Other
- 11497
- 11498
- 11563
- 11568
- 11569
- 11570
- 11571
- 11712
- 11713
- 11714
- 11453
- 11454
- 11583
- 11644
- 11645
- 11646
- 11766
- 11767
- 11768
- 10729
- 10735
- 10852
- 10853
- 10816
Security Updates (7)
Acknowledgments
James Forshaw of <a href="http://www.google.com/">Google Project Zero</a>
Revision History
- 2020-09-08: Information published.