Windows Denial of Service Vulnerability
Published May 21, 2020
5.5
MEDIUMCVSS 3.1
EPSS 1.09%
Description
A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would not allow an attacker to execute code or to elevate user rights directly, but it could be used to cause a target system to stop responding. The update addresses the vulnerability by correcting how Windows handles objects in memory.
Affected products
-
Affected
- ≥ 10.0.10240.0, < publication
-
Affected
- ≥ 10.0.14393.0, < publication
-
Affected
- ≥ 10.0.0, < publication
-
Affected
- ≥ 10.0.0, < publication
-
Affected
- ≥ 10.0.0, < publication
-
Affected
- ≥ 10.0.0, < publication
- ≥ 10.0.17763.0, < publication
-
Affected
- ≥ 10.0.0, < publication
-
Affected
- ≥ 10.0.0, < publication
-
Affected
- ≥ 10.0.0, < publication
-
Affected
- ≥ 10.0.0, < publication
-
Affected
- ≥ 6.3.0, < publication
-
Affected
- ≥ 6.2.9200.0, < publication
-
Affected
- ≥ 6.2.9200.0, < publication
-
Affected
- ≥ 6.3.9600.0, < publication
-
Affected
- ≥ 6.3.9600.0, < publication
-
Affected
- ≥ 10.0.14393.0, < publication
-
Affected
- ≥ 10.0.14393.0, < publication
-
Affected
- ≥ 10.0.17763.0, < publication
-
Affected
- ≥ 10.0.17763.0, < publication
-
Affected
- ≥ 10.0.0, < publication
-
Affected
- ≥ 10.0.0, < publication
-
Affected
- ≥ 10.0.0, < publication
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Microsoft | Windows 10 Version 1507 | unknown | Affected
|
| Microsoft | Windows 10 Version 1607 | unknown | Affected
|
| Microsoft | Windows 10 Version 1709 | unknown | Affected
|
| Microsoft | Windows 10 Version 1709 for 32-bit Systems | unknown | Affected
|
| Microsoft | Windows 10 Version 1803 | unknown | Affected
|
| Microsoft | Windows 10 Version 1809 | unknown | Affected
|
| Microsoft | Windows 10 Version 1903 for 32-bit Systems | unknown | Affected
|
| Microsoft | Windows 10 Version 1903 for ARM64-based Systems | unknown | Affected
|
| Microsoft | Windows 10 Version 1903 for x64-based Systems | unknown | Affected
|
| Microsoft | Windows 10 Version 1909 | unknown | Affected
|
| Microsoft | Windows 8.1 | unknown | Affected
|
| Microsoft | Windows Server 2012 | unknown | Affected
|
| Microsoft | Windows Server 2012 (Server Core installation) | unknown | Affected
|
| Microsoft | Windows Server 2012 R2 | unknown | Affected
|
| Microsoft | Windows Server 2012 R2 (Server Core installation) | unknown | Affected
|
| Microsoft | Windows Server 2016 | unknown | Affected
|
| Microsoft | Windows Server 2016 (Server Core installation) | unknown | Affected
|
| Microsoft | Windows Server 2019 | unknown | Affected
|
| Microsoft | Windows Server 2019 (Server Core installation) | unknown | Affected
|
| Microsoft | Windows Server, version 1803 (Server Core Installation) | unknown | Affected
|
| Microsoft | Windows Server, version 1903 (Server Core installation) | unknown | Affected
|
| Microsoft | Windows Server, version 1909 (Server Core installation) | unknown | Affected
|
- n/a
- 1607
- 1709
- 1803
- 1809
- 1903
- 1909
- n/a
- n/a
- n/a
- n/a
- r2
- r2
- n/a
- r2
- n/a
- n/a
- 1903
- 1909
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-11966 Advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-1076 vendor-advisorypatch
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1076 PatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-11966 | Advisory | |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-1076 | vendor-advisorypatch | |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1076 | PatchVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data