CVE-2020-1283 — Windows Denial of Service Vulnerability
Executive Summary
A denial of service vulnerability exists when Windows improperly handles objects in memory. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application or to convince a user to open a specific file on a network share. The vulnerability would not allow an attacker to execute code or to elevate user rights directly, but it could be used to cause a target system to stop responding. The update addresses the vulnerability by correcting how Windows handles objects in memory.
Overview
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 Version 1607 for 32-bit Systems | 4561616 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1607 for x64-based Systems | 4561616 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1709 for 32-bit Systems | 4561602 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1709 for ARM64-based Systems | 4561602 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1709 for x64-based Systems | 4561602 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1803 for 32-bit Systems | 4561621 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1803 for ARM64-based Systems | 4561621 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1803 for x64-based Systems | 4561621 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 4561608 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1809 for ARM64-based Systems | 4561608 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1809 for x64-based Systems | 4561608 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1903 for 32-bit Systems | 4560960 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1903 for ARM64-based Systems | 4560960 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1903 for x64-based Systems | 4560960 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1909 for 32-bit Systems | 4560960 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1909 for ARM64-based Systems | 4560960 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 1909 for x64-based Systems | 4560960 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 2004 for 32-bit Systems | 4557957 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 2004 for ARM64-based Systems | 4557957 (Security Update) |
Important | Denial of Service | Yes |
| Windows 10 Version 2004 for x64-based Systems | 4557957 (Security Update) |
Important | Denial of Service | Yes |
| Windows Server 2016 | 4561616 (Security Update) |
Important | Denial of Service | Yes |
| Windows Server 2016 (Server Core installation) | 4561616 (Security Update) |
Important | Denial of Service | Yes |
| Windows Server 2019 | 4561608 (Security Update) |
Important | Denial of Service | Yes |
| Windows Server 2019 (Server Core installation) | 4561608 (Security Update) |
Important | Denial of Service | Yes |
| Windows Server, version 1803 (Server Core Installation) | 4561621 (Security Update) |
Important | Denial of Service | Yes |
| Windows Server, version 1903 (Server Core installation) | 4560960 (Security Update) |
Important | Denial of Service | Yes |
| Windows Server, version 1909 (Server Core installation) | 4560960 (Security Update) |
Important | Denial of Service | Yes |
| Windows Server, version 2004 (Server Core installation) | 4557957 (Security Update) |
Important | Denial of Service | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
4561616 |
Security Update | Yes |
4561602 |
Security Update | Yes |
4561621 |
Security Update | Yes |
4561608 |
Security Update | Yes |
4560960 |
Security Update | Yes |
4557957 |
Security Update | Yes |
Exploits & PoC
1 public PoCUnverified third-party code
Public proof-of-concept repositories aggregated from PoC-in-GitHub. They are not reviewed and may be incomplete, non-functional, or malicious — inspect the code before running anything.
| Repository | Stars | Published | Description |
|---|---|---|---|
| RedyOpsResearchLabs/CVE-2020-1283_Windows-Denial-of-Service-Vulnerability | 7 | 2020-04-17 | Exploit Code for CVE-2020-1283 - Windows-Denial-of-Service-Vulnerability |
Detection Rules
Acknowledgments
Ilias Dimopoulos of RedyOps Research Labs
Gábor Selján ( @GaborSeljan
Zhiniang Peng ( @edwardzpeng