← Back to browse · API

CVE-2020-1054

Severity
HIGH
CVSS
7.8
EPSS
0.52778
Risk score
74.67
CISA KEV
Yes
PoC
No
Published
2021-11-03
Modified
2021-11-03
First seen
2026-08-07
Aliases
EUVD-2020-11947, GHSA-5QFV-HVXP-FG32
Products
Microsoft:Win32k, Microsoft:Windows 10 Version 1607 for 32-bit Systems, Microsoft:Windows 10 Version 1607 for x64-based Systems, Microsoft:Windows 10 Version 1709 for 32-bit Systems, Microsoft:Windows 10 Version 1709 for ARM64-based Systems, Microsoft:Windows 10 Version 1709 for x64-based Systems, Microsoft:Windows 10 Version 1803 for 32-bit Systems, Microsoft:Windows 10 Version 1803 for ARM64-based Systems, Microsoft:Windows 10 Version 1803 for x64-based Systems, Microsoft:Windows 10 Version 1809 for 32-bit Systems, Microsoft:Windows 10 Version 1809 for ARM64-based Systems, Microsoft:Windows 10 Version 1809 for x64-based Systems, Microsoft:Windows 10 Version 1903 for 32-bit Systems unspecified, Microsoft:Windows 10 Version 1903 for ARM64-based Systems unspecified, Microsoft:Windows 10 Version 1903 for x64-based Systems unspecified, Microsoft:Windows 10 Version 1909 for 32-bit Systems unspecified, Microsoft:Windows 10 Version 1909 for ARM64-based Systems unspecified, Microsoft:Windows 10 Version 1909 for x64-based Systems unspecified, Microsoft:Windows 10 for 32-bit Systems, Microsoft:Windows 10 for x64-based Systems, Microsoft:Windows 7 for 32-bit Systems Service Pack 1, Microsoft:Windows 7 for x64-based Systems Service Pack 1, Microsoft:Windows 8.1 for 32-bit systems, Microsoft:Windows 8.1 for x64-based systems, Microsoft:Windows RT 8.1, Microsoft:Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1, Microsoft:Windows Server 2008 R2 for x64-based Systems Service Pack 1, Microsoft:Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Core installation), Microsoft:Windows Server 2008 for 32-bit Systems Service Pack 2, Microsoft:Windows Server 2008 for 32-bit Systems Service Pack 2 (Core installation), Microsoft:Windows Server 2008 for Itanium-Based Systems Service Pack 2, Microsoft:Windows Server 2008 for x64-based Systems Service Pack 2, Microsoft:Windows Server 2008 for x64-based Systems Service Pack 2 (Core installation), Microsoft:Windows Server 2012, Microsoft:Windows Server 2012 (Core installation), Microsoft:Windows Server 2012 R2, Microsoft:Windows Server 2012 R2 (Core installation), Microsoft:Windows Server 2016, Microsoft:Windows Server 2016 (Core installation), Microsoft:Windows Server 2019, Microsoft:Windows Server 2019 (Core installation), Microsoft:Windows Server version 1803 (Core Installation), Microsoft:Windows Server, version 1903 (Server Core installation) unspecified, Microsoft:Windows Server, version 1909 (Server Core installation) unspecified
Sources
euvd EUVD-2020-11947
cisa.gov CVE-2020-1054

Description

Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.

References