CVE-2020-0668

HIGH

Microsoft Windows 10 - Incorrect Permission Assignment

Title source: rule

Description

An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0669, CVE-2020-0670, CVE-2020-0671, CVE-2020-0672.

Exploits (7)

nomisec WORKING POC 229 stars
by RedCursorSecurityConsulting · poc
https://github.com/RedCursorSecurityConsulting/CVE-2020-0668
nomisec WORKING POC 14 stars
by ycdxsb · poc
https://github.com/ycdxsb/CVE-2020-0668
nomisec WORKING POC 6 stars
by Nan3r · poc
https://github.com/Nan3r/CVE-2020-0668
nomisec WORKING POC 2 stars
by modulexcite · poc
https://github.com/modulexcite/SysTracingPoc
nomisec WRITEUP 1 stars
by bypazs · poc
https://github.com/bypazs/CVE-2020-0668.exe
nomisec WORKING POC
by 0xSs0rZ · poc
https://github.com/0xSs0rZ/Windows_Exploit
metasploit WORKING POC EXCELLENT
by itm4n, bwatters-r7 · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/cve_2020_0668_service_tracing.rb

Scores

CVSS v3 7.8
EPSS 0.8089
EPSS Percentile 99.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (19)
microsoft/windows_10
microsoft/windows_10 1607
microsoft/windows_10 1709
microsoft/windows_10 1803
microsoft/windows_10 1809
microsoft/windows_10 1903
microsoft/windows_10 1909
microsoft/windows_7
microsoft/windows_8.1
microsoft/windows_rt_8.1
... and 9 more
Published Feb 11, 2020
Tracked Since Feb 18, 2026