VYPR
High severity7.0NVD Advisory· Published May 21, 2020· Updated Aug 19, 2026

CVE-2020-1143

CVE-2020-1143

Description

An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. The update addresses this vulnerability by correcting how the Windows kernel-mode driver handles objects in memory.

Affected products

33
  • Range: version 1803 (Core Installation)
  • Microsoft/Windowsllm-fuzzy2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 10 Version 1803 for 32-bit Systems
  • Microsoft/Windows 10 Version 1909 for 32-bit Systemsv5
    Range: unspecified
  • Microsoft/Windows 10 Version 1909 for x64-based Systemsv5
    Range: unspecified
  • Microsoft/Windows 10 Version 1909 for ARM64-based Systemsv5
    Range: unspecified
  • Microsoft/Windows Server, version 1909 (Server Core installation)v5
    Range: unspecified
  • Microsoft/Windows 10 Version 1903 for 32-bit Systemsv5
    Range: unspecified
  • Microsoft/Windows 10 Version 1903 for x64-based Systemsv5
    Range: unspecified
  • Microsoft/Windows 10 Version 1903 for ARM64-based Systemsv5
    Range: unspecified
  • Microsoft/Windows Server, version 1903 (Server Core installation)v5
    Range: unspecified
  • cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:x64:*+ 8 more
    • cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:x64:*
    • cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:x86:*
    • cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:x64:*
    • cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:x86:*
    • cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_10:1903:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_10:1909:*:*:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:x64:*+ 1 more
    • cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:x64:*
    • cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:x86:*
  • cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:x64:*+ 1 more
    • cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:x64:*
    • cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:x86:*
  • cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:itanium:*+ 3 more
    • cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:itanium:*
    • cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x64:*
    • cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x86:*
    • cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x86:*
  • cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.