CVE-2020-0794 — Windows Denial of Service Vulnerability
Executive Summary
A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would not allow an attacker to execute code or to elevate user rights directly, but it could be used to cause a target system to stop responding. The update addresses the vulnerability by correcting how Windows handles objects in memory.
Overview
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 for 32-bit Systems | 4571692 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 for x64-based Systems | 4571692 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1607 for 32-bit Systems | 4571694 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1607 for x64-based Systems | 4571694 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1709 for 32-bit Systems | 4550927 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1709 for ARM64-based Systems | 4550927 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1709 for x64-based Systems | 4550927 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1803 for 32-bit Systems | 4550922 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1803 for ARM64-based Systems | 4550922 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1803 for x64-based Systems | 4550922 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 4549949 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1809 for ARM64-based Systems | 4549949 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1809 for x64-based Systems | 4549949 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1903 for 32-bit Systems | 4549951 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1903 for ARM64-based Systems | 4549951 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1903 for x64-based Systems | 4549951 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1909 for 32-bit Systems | 4549951 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1909 for ARM64-based Systems | 4549951 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1909 for x64-based Systems | 4549951 (Security Update) |
Important | Denial of Service | Yes |
| Windows Server 2016 | 4571694 (Security Update) |
Important | Denial of Service | Yes |
| Windows Server 2016 (Server Core installation) | 4571694 (Security Update) |
Important | Denial of Service | Yes |
| Windows Server 2019 | 4549949 (Security Update) |
Important | Denial of Service | Yes |
| Windows Server 2019 (Server Core installation) | 4549949 (Security Update) |
Important | Denial of Service | Yes |
| Windows Server, version 1803 (Server Core Installation) | 4550922 (Security Update) |
Important | Denial of Service | Yes |
| Windows Server, version 1903 (Server Core installation) | 4549951 (Security Update) |
Important | Denial of Service | Yes |
| Windows Server, version 1909 (Server Core installation) | 4549951 (Security Update) |
Important | Denial of Service | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
4571692 |
Security Update | Yes |
4571694 |
Security Update | Yes |
4550927 |
Security Update | Yes |
4550922 |
Security Update | Yes |
4549949 |
Security Update | Yes |
4549951 |
Security Update | Yes |
Known Exploits
Acknowledgments
Trend Micro's Zero Day Initiative, Nadav Markus, Zhiniang Peng (@edwardzpeng) of Qihoo 360 Core security and Fangming Gu (@afang5472), Jarvis_1oop of Pinduoduo Security Research Lab, k0shl of Qihoo 360 Vulcan team