ENISA EUVD · EUVD-2020-11947Known-exploited evidence recordedAn elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.
The update addresses this vulnerability by correcting how the Windows kernel-mode driver handles objects in memory.
Official EUVD record ↗KISA KrCERT/CC · Korean · KNVD-5139MS 5월 보안 위협에 따른 정기 보안 업데이트 권고- 권한상승 취약점(CVE-2020-1010, CVE-2020-1021, CVE-2020-1048, CVE-2020-1054, CVE-2020-1056, CVE-2020-1068, CVE-2020-1070, CVE-2020-1071, CVE-2020-1077, CVE-2020-1078, CVE-2020-1079, CVE-2020-1081, CVE-2020-1082, CVE-2020-1086, CVE-2020-1087, CVE-2020-1088, CVE-2020-1090, CVE-2020-1109, CVE-2020-1110, CVE-2020-1111, CVE-2020-1112, CVE-2020-1114, CVE-2020-1121, CVE-2020-1124, CVE-2020-1125, CVE-2020-1131, CVE-2020-1132, CVE-2020-1134, CVE-2020-1135, CVE-2020-1137, CVE-2020-1138, CVE-2020-1139, CVE-2020-1140, CVE-2020-1142, CVE-2020-1143, CVE-2020-1144, CVE-2020-1149, CVE-2020-1151, CVE-2020-1154, CVE-2020-1155, CVE-2020-1156, CVE-2020-1157, CVE-2020-1158, CVE-2020-1164, CVE-2020-1165, CVE-2020-1166, CVE-2020-1184, CVE-2020-1185, CVE-2020-1186, CVE-2020-1187, CVE-2020-1188, CVE-2020-1189, CVE-2020-1190, CVE-2020-1191)
Official advisory ↗