Back

HIGH

Windows Remote Code Execution Vulnerability

Published May 21, 2020

Description

A remote code execution vulnerability exists in the way that Windows handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with elevated permissions on a target system. To exploit the vulnerability, an attacker who has a domain user account could create a specially crafted request, causing Windows to execute arbitrary code with elevated permissions. The security update addresses the vulnerability by correcting how Windows handles objects in memory.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (0)

No CWE recorded.

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner microsoft
Published May 21, 2020
Updated Aug 19, 2026
Reserved Nov 4, 2019

CISA Vulnrichment

No data

NVD

Status Modified
Modified Aug 19, 2026

Red Hat

No data

ENISA EUVD

Assigner microsoft
Published May 21, 2020
Updated Aug 19, 2026

GitHub

No data