Описание
Multiple vulnerabilities were found in Microsoft ESU products. Malicious users can exploit these vulnerabilities to gain privileges, obtain sensitive information, cause denial of service, execute arbitrary code.
Below is a complete list of vulnerabilities:
- An elevation of privilege vulnerability in NTFS can be exploited remotely via specially crafted application to gain privileges.
- An information disclosure vulnerability in Windows GDI can be exploited remotely via specially crafted document to obtain sensitive information.
- An information disclosure vulnerability in Active Directory can be exploited remotely via specially crafted request to obtain sensitive information.
- A denial of service vulnerability in Windows DNS can be exploited remotely to cause denial of service.
- A remote code execution vulnerability in GDI+ can be exploited remotely via specially crafted website to execute arbitrary code.
- A remote code execution vulnerability in Jet Database Engine can be exploited remotely via specially crafted file to execute arbitrary code.
- Unspecified Windows Routing Utilities can be exploited remotely via specially crafted application to cause denial of service.
- An elevation of privilege vulnerability in Group Policy can be exploited remotely to gain privileges.
- An information disclosure vulnerability in Microsoft Graphics Component can be exploited remotely via specially crafted application to obtain sensitive information.
- A remote code execution vulnerability in Microsoft COM for Windows can be exploited remotely via specially crafted file to execute arbitrary code.
- An information disclosure vulnerability in Windows DHCP Server can be exploited remotely via specially crafted packet to obtain sensitive information.
- An elevation of privilege vulnerability in Windows Print Spooler can be exploited remotely via specially crafted script to gain privileges.
- A remote code execution vulnerability in Windows can be exploited remotely via specially crafted application to execute arbitrary code.
- A memory corruption vulnerability in Microsoft Browser can be exploited remotely via specially crafted website to execute arbitrary code.
- An elevation of privilege vulnerability in Windows Common Log File System Driver can be exploited remotely via specially crafted application to gain privileges.
- An information disclosure vulnerability in TLS can be exploited remotely to obtain sensitive information.
- An elevation of privilege vulnerability in Windows can be exploited remotely via specially crafted application to gain privileges.
- An elevation of privilege vulnerability in Windows Function Discovery Service can be exploited remotely via specially crafted application to gain privileges.
- A remote code execution vulnerability in Windows Media Audio Decoder can be exploited remotely via specially crafted document to execute arbitrary code.
- An information disclosure vulnerability in Windows Graphics Component can be exploited remotely via specially crafted document to obtain sensitive information.
- An elevation of privilege vulnerability in Windows Cryptographic Catalog Services can be exploited remotely via specially crafted application to gain privileges.
- An elevation of privilege vulnerability in Win32k can be exploited remotely via specially crafted application to gain privileges.
- An elevation of privilege vulnerability in Windows RSoP Service Application can be exploited remotely via specially crafted application to gain privileges.
- An elevation of privilege vulnerability in Windows Storage Services can be exploited remotely via specially crafted application to gain privileges.
- An elevation of privilege vulnerability in Windows Modules Installer can be exploited remotely via specially crafted application to gain privileges.
- An elevation of privilege vulnerability in Windows Function Discovery SSDP Provider can be exploited remotely via specially crafted application to gain privileges.
- An elevation of privilege vulnerability in Windows UPnP Service can be exploited remotely via specially crafted script to gain privileges.
- A remote code execution vulnerability in Active Directory can be exploited remotely to execute arbitrary code.
- An information disclosure vulnerability in Windows Kernel can be exploited remotely via specially crafted application to obtain sensitive information.
- An information disclosure vulnerability in Win32k can be exploited remotely via specially crafted application to obtain sensitive information.
- An elevation of privilege vulnerability in Microsoft splwow64 can be exploited remotely to gain privileges.
Первичный источник обнаружения
- CVE-2020-0838
CVE-2020-1256
CVE-2020-0856
CVE-2020-0836
CVE-2020-1285
CVE-2020-1039
CVE-2020-1038
CVE-2020-1013
CVE-2020-0921
CVE-2020-0922
CVE-2020-1031
CVE-2020-1030
CVE-2020-1252
CVE-2020-0878
CVE-2020-1115
CVE-2020-1596
CVE-2020-1052
CVE-2020-1491
CVE-2020-1593
CVE-2020-0664
CVE-2020-1097
CVE-2020-0782
CVE-2020-1245
CVE-2020-0648
CVE-2020-1091
CVE-2020-1559
CVE-2020-1074
CVE-2020-0911
CVE-2020-0912
CVE-2020-1228
CVE-2020-1598
CVE-2020-1376
CVE-2020-0718
CVE-2020-1083
CVE-2020-1589
CVE-2020-1250
CVE-2020-0790
CVE-2020-1508
CVE-2020-0761
Эксплуатация
Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.
Связанные продукты
- Microsoft-Internet-Explorer
- Microsoft-Windows
- Microsoft-Windows-Server
- Microsoft-Windows-Server-2012
- Microsoft-Windows-8
- Microsoft-Windows-7
- Microsoft-Windows-Server-2008
- Windows-RT
- Microsoft-Windows-10
- Microsoft-Edge
- ChakraCore
Список CVE
- CVE-2020-0838 critical
- CVE-2020-0922 critical
- CVE-2020-1250 high
- CVE-2020-0856 high
- CVE-2020-0836 critical
- CVE-2020-1228 critical
- CVE-2020-1038 high
- CVE-2020-1013 critical
- CVE-2020-1598 high
- CVE-2020-1031 critical
- CVE-2020-1030 critical
- CVE-2020-1252 critical
- CVE-2020-1115 critical
- CVE-2020-1052 critical
- CVE-2020-1491 critical
- CVE-2020-1593 critical
- CVE-2020-0664 high
- CVE-2020-0782 critical
- CVE-2020-1245 high
- CVE-2020-0648 critical
- CVE-2020-1091 high
- CVE-2020-1559 critical
- CVE-2020-1596 high
- CVE-2020-1074 critical
- CVE-2020-1256 high
- CVE-2020-1285 critical
- CVE-2020-0911 critical
- CVE-2020-0912 high
- CVE-2020-1039 critical
- CVE-2020-1376 critical
- CVE-2020-0718 critical
- CVE-2020-1083 high
- CVE-2020-1589 warning
- CVE-2020-0790 critical
- CVE-2020-1097 high
- CVE-2020-1508 critical
- CVE-2020-0761 critical
- CVE-2020-0921 high
- CVE-2020-0878 warning
Список KB
Смотрите также
Узнай статистику распространения уязвимостей в своем регионе statistics.securelist.com
Нашли неточность в описании этой уязвимости? Дайте нам знать!