CVE-2020-1113

HIGH

Windows Task Scheduler - Security Feature Bypass via Improper RPC Client Connection Verification

Title source: llm
STIX 2.1

Description

A security feature bypass vulnerability exists in Microsoft Windows when the Task Scheduler service fails to properly verify client connections over RPC, aka 'Windows Task Scheduler Security Feature Bypass Vulnerability'.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0728
EPSS Percentile 93.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-295
Status published
Products (17)
microsoft/windows_10 (2 CPE variants)
microsoft/windows_10 1607 (2 CPE variants)
microsoft/windows_10 1709
microsoft/windows_10 1803
microsoft/windows_10 1809
microsoft/windows_10 1903
microsoft/windows_10 1909
microsoft/windows_7 (2 CPE variants)
microsoft/windows_8.1 (2 CPE variants)
microsoft/windows_rt_8.1
... and 7 more
Published May 21, 2020
Tracked Since Feb 18, 2026