CVE-2020-1471: Windows CloudExperienceHost Elevation of Privilege Vulnerability

Overview

Severity
Medium (CVSS 6.1)
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N/E:P/RL:O/RC:C
Category
Elevation of Privilege
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2020-Sep
Released
2020-09-08
EPSS Score
0.68% (percentile: 71.7%)

Description

An elevation of privilege vulnerability exists when Microsoft Windows CloudExperienceHost fails to check COM objects. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system. To exploit the vulnerability, an attacker would have to log on to an affected system and run a specially crafted script or application. The security update addresses the vulnerability by checking COM objects.

Affected Products (24)

Other

  • 11497
  • 11498
  • 11563
  • 11568
  • 11569
  • 11570
  • 11571
  • 11712
  • 11713
  • 11714
  • 11453
  • 11454
  • 11583
  • 11644
  • 11645
  • 11646
  • 11766
  • 11767
  • 11768
  • 10729
  • 10735
  • 10852
  • 10853
  • 10816

Security Updates (7)

Acknowledgments

James Forshaw of <a href="http://www.google.com/">Google Project Zero</a>

Revision History

  • 2020-09-08: Information published.