CVE-2020-1054
HIGH KEVWindows - Privilege Escalation
Title source: llmDescription
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1143.
Exploits (7)
metasploit
WORKING POC
NORMAL
by Netanel Ben-Simon, Yoav Alon, bee13oy, timwr · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/cve_2020_1054_drawiconex_lpe.rb
References (3)
Scores
CVSS v3
7.8
EPSS
0.8183
EPSS Percentile
99.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2021-11-03
VulnCheck KEV
2020-10-19
InTheWild.io
2021-07-23
ENISA EUVD
EUVD-2020-11947
CWE
CWE-787
Status
published
Products (19)
microsoft/windows_10_1507
(2 CPE variants)
microsoft/windows_10_1607
(2 CPE variants)
microsoft/windows_10_1709
(3 CPE variants)
microsoft/windows_10_1803
(3 CPE variants)
microsoft/windows_10_1809
(3 CPE variants)
microsoft/windows_10_1903
(3 CPE variants)
microsoft/windows_10_1909
(3 CPE variants)
microsoft/windows_7
microsoft/windows_8.1
microsoft/windows_rt_8.1
... and 9 more
Published
May 21, 2020
KEV Added
Nov 03, 2021
Tracked Since
Feb 18, 2026