VYPR
High severity7.8NVD Advisory· Published Oct 16, 2020· Updated Jun 17, 2026

CVE-2020-16907

CVE-2020-16907

Description

An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. The update addresses this vulnerability by correcting how the Windows kernel-mode driver handles objects in memory.

Affected products

15
  • cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*+ 1 more
    • cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*range: 10.0.0
    • cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*range: 10.0.0
  • cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*range: 10.0.0
    • cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_10_1909:*:*:*:*:*:*:x86:*+ 6 more
    • cpe:2.3:o:microsoft:windows_10_1909:*:*:*:*:*:*:x86:*range: 10.0.0
    • cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_10:1903:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_10:1909:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_10:2004:*:*:*:*:*:*:*
  • cpe:2.3:o:microsoft:windows_server_2016:1903:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:microsoft:windows_server_2016:1903:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_server_2016:1909:*:*:*:*:*:*:*
    • cpe:2.3:o:microsoft:windows_server_2016:2004:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.