CVE-2020-17087 — Windows Kernel Local Elevation of Privilege Vulnerability
Executive Summary
None
Overview
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 for 32-bit Systems | 4586787 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 for x64-based Systems | 4586787 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1607 for 32-bit Systems | 4586830 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1607 for x64-based Systems | 4586830 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1803 for 32-bit Systems | 4586785 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1803 for ARM64-based Systems | 4586785 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1803 for x64-based Systems | 4586785 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 4586793 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for ARM64-based Systems | 4586793 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for x64-based Systems | 4586793 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1903 for 32-bit Systems | 4586786 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1903 for ARM64-based Systems | 4586786 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1903 for x64-based Systems | 4586786 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1909 for 32-bit Systems | 4586786 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1909 for ARM64-based Systems | 4586786 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1909 for x64-based Systems | 4586786 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 2004 for 32-bit Systems | 4586781 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 2004 for ARM64-based Systems | 4586781 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 2004 for x64-based Systems | 4586781 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 20H2 for 32-bit Systems | 4586781 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 20H2 for ARM64-based Systems | 4586781 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 7 for 32-bit Systems Service Pack 1 4586827 (Monthly Rollup) 4586805 (Security Only) Important Elevation of Privilege 4580345 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C Yes 4586827 4586805 Windows 7 for x64-based Systems Service Pack 1 4586827 (Monthly Rollup) 4586805 (Security Only) Important Elevation of Privilege 4580345 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C Yes 4586827 4586805 Windows 8.1 for 32-bit systems 4586845 (Monthly Rollup) 4586823 (Security Only) Important Elevation of Privilege 4580347 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C Yes 4586845 4586823 Windows 8.1 for x64-based systems 4586845 (Monthly Rollup) 4586823 (Security Only) Important Elevation of Privilege 4580347 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C Yes 4586845 4586823 Windows RT 8.1 | 4586845 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2008 for 32-bit Systems Service Pack 2 4586807 (Monthly Rollup) 4586817 (Security Only) Important Elevation of Privilege 4580378 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C Yes 4586807 4586817 Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 4586807 (Monthly Rollup) 4586817 (Security Only) Important Elevation of Privilege 4580378 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C Yes 4586807 4586817 Windows Server 2008 for x64-based Systems Service Pack 2 4586807 (Monthly Rollup) 4586817 (Security Only) Important Elevation of Privilege 4580378 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C Yes 4586807 4586817 Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 4586807 (Monthly Rollup) 4586817 (Security Only) Important Elevation of Privilege 4580378 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C Yes 4586807 4586817 Windows Server 2008 R2 for x64-based Systems Service Pack 1 4586827 (Monthly Rollup) 4586805 (Security Only) Important Elevation of Privilege 4580345 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C Yes 4586827 4586805 Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 4586827 (Monthly Rollup) 4586805 (Security Only) Important Elevation of Privilege 4580345 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C Yes 4586827 4586805 Windows Server 2012 4598278 (Monthly Rollup) 4598297 (Security Only) Important Elevation of Privilege 4592468 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C Yes 4598278 4598297 Windows Server 2012 (Server Core installation) 4598278 (Monthly Rollup) 4598297 (Security Only) Important Elevation of Privilege 4592468 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C Yes 4598278 4598297 Windows Server 2012 R2 4586845 (Monthly Rollup) 4586823 (Security Only) Important Elevation of Privilege 4580347 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C Yes 4586845 4586823 Windows Server 2012 R2 (Server Core installation) 4586845 (Monthly Rollup) 4586823 (Security Only) Important Elevation of Privilege 4580347 Base: 7.8 Temporal: 7.2 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C Yes 4586845 4586823 Windows Server 2016 | 4586830 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2016 (Server Core installation) | 4586830 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 | 4586793 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 (Server Core installation) | 4586793 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server, version 1903 (Server Core installation) | 4586786 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server, version 1909 (Server Core installation) | 4586786 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server, version 2004 (Server Core installation) | 4586781 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server, version 20H2 (Server Core Installation) | 4586781 (Security Update) |
Important | Elevation of Privilege | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
4586787 |
Security Update | Yes |
4586830 |
Security Update | Yes |
4586785 |
Security Update | Yes |
4586793 |
Security Update | Yes |
4586786 |
Security Update | Yes |
4586781 |
Security Update | Yes |
4586845 |
Monthly Rollup | Yes |
Patch Diff
Pool buffer overflow (CWE-190 integer truncation) in cng.sys IOCTL 0x390400 handling: cng!CfgAdtpFormatPropertyBlock computes the output allocation as SrcLen*6 in 16-bit arithmetic but writes SrcLen*6 bytes of Unicode hex dump, giving a controlled-length linear NonPagedPoolNx overflow with a XX 00 XX 00 20 00 byte pattern. Reachable by any local user via DeviceIoControl on \\.\GLOBALROOT\Device\Cng (or BCryptSetContextFunctionProperty). Exploited ITW as the sandbox-escape stage of a Chrome chain (with CVE-2020-15999); full public technique via Segment Heap BlockSize attack + named-pipe DQE abuse + quota ProcessBilled decrement -> SeDebugPrivilege (PixiePoint). Patch (KB4586781, cng.sys 10.0.19041.630) replaces the inline multiply with new helper RtlUShortMult and rejects on overflow; VERIFIED 2026-07-22 via ghidriff + headless decompile (single code-changed function).
| Function | Address | Change | Note |
|---|---|---|---|
cng!CfgAdtpFormatPropertyBlock |
0x1c006245c (both builds) |
code (verified via headless decompile 2026-07-22) | 16-bit truncation: BCryptAlloc((USHORT)(SrcLen*6)) while the hex-format loop writes SrcLen*6 bytes -> NonPagedPoolNx linear overflow ('Cngb' tag), content pattern XX 00 XX 00 20 00. SrcLen>=0x2AAB triggers ((ushort)(0x2AAB*6)=2 allocated, 0x10002 written). Length also truncated to 16-bit at the CfgAdtReportFunctionPropertyOperation call site. Fix: RtlUShortMult(len,6,&out) with error-on-overflow before allocation + BCryptFree cleanup path. |
cng!RtlUShortMult |
|
added | Safe 16-bit multiply returning error on overflow; the entire fix |
cng!BCryptFree |
|
modified (no code changes) | metadata-only churn |
Known Exploits
Acknowledgments
Microsoft would like to thank Qualys for co-ordinated vulnerability disclosure on identifying a regression for the Windows Server 2012 version of this security update.
Mateusz Jurczyk and Sergei Glazunov of Google Project Zero