packetstormsecurity.com
http://packetstormsecurity.com/files/168068/Windows-sxs-CNodeFactory-XMLParser_Element_doc_assembly_assemblyIdentity-Heap-Buffer-Overflow.html CVE-2020-1027
HIGHCISA KEV
Microsoft Windows Kernel Privilege Escalation Vulnerability
Record summary
CVE-2020-1027 has a selected CVSS score of 7.8 (high). CISA lists CVE-2020-1027 in KEV.
Description
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0913, CVE-2020-1000, CVE-2020-1003.
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · May 23, 2022 · CISA
- VulnCheck KEV
- Listed · Mar 23, 2020 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 7, 2025 · Source: CVE List
Affected products and versions
10| Product | Source | Version range | Status |
|---|---|---|---|
WindowsBrowse Microsoft / Windows | CISA, CVE List | 10 Version 1803 for 32-bit Systems | affected |
| 10 Version 1803 for x64-based Systems | affected | ||
| 10 Version 1803 for ARM64-based Systems | affected | ||
| 10 Version 1809 for 32-bit Systems | affected | ||
| 10 Version 1809 for x64-based Systems | affected | ||
| 10 Version 1809 for ARM64-based Systems | affected | ||
| 10 Version 1709 for 32-bit Systems | affected | ||
| 10 Version 1709 for x64-based Systems | affected | ||
| 10 Version 1709 for ARM64-based Systems | affected | ||
| 10 for 32-bit Systems | affected | ||
| 10 for x64-based Systems | affected | ||
| 10 Version 1607 for 32-bit Systems | affected | ||
| Showing 12 of 18 version ranges | |||
Windows 10 Version 1903 for 32-bit SystemsBrowse Microsoft / Windows 10 Version 1903 for 32-bit Systems | CVE List | Version range not supplied | affected |
Windows 10 Version 1903 for ARM64-based SystemsBrowse Microsoft / Windows 10 Version 1903 for ARM64-based Systems | CVE List | Version range not supplied | affected |
Windows 10 Version 1903 for x64-based SystemsBrowse Microsoft / Windows 10 Version 1903 for x64-based Systems | CVE List | Version range not supplied | affected |
Windows 10 Version 1909 for 32-bit SystemsBrowse Microsoft / Windows 10 Version 1909 for 32-bit Systems | CVE List | Version range not supplied | affected |
Windows 10 Version 1909 for ARM64-based SystemsBrowse Microsoft / Windows 10 Version 1909 for ARM64-based Systems | CVE List | Version range not supplied | affected |
Windows 10 Version 1909 for x64-based SystemsBrowse Microsoft / Windows 10 Version 1909 for x64-based Systems | CVE List | Version range not supplied | affected |
Windows ServerBrowse Microsoft / Windows Server | CVE List | version 1803 (Core Installation) | affected |
| 2019 | affected | ||
| 2019 (Core installation) | affected | ||
| 2016 | affected | ||
| 2016 (Core installation) | affected | ||
| 2008 for 32-bit Systems Service Pack 2 | affected | ||
| 2008 for 32-bit Systems Service Pack 2 (Core installation) | affected | ||
| 2008 for Itanium-Based Systems Service Pack 2 | affected | ||
| 2008 for x64-based Systems Service Pack 2 | affected | ||
| 2008 for x64-based Systems Service Pack 2 (Core installation) | affected | ||
| 2008 R2 for Itanium-Based Systems Service Pack 1 | affected | ||
| 2008 R2 for x64-based Systems Service Pack 1 | affected | ||
| Showing 12 of 17 version ranges | |||
Windows Server, version 1903 (Server Core installation)Browse Microsoft / Windows Server, version 1903 (Server Core installation) | CVE List | Version range not supplied | affected |
Windows Server, version 1909 (Server Core installation)Browse Microsoft / Windows Server, version 1909 (Server Core installation) | CVE List | Version range not supplied | affected |
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-1027 portal.msrc.microsoft.com
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1027 cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-1027