CVE-2020-1548

HIGH

Windows 10 and Windows Server 2016/2019 - Information Disclosure in WaasMedic Service

Title source: llm
STIX 2.1

Description

An information disclosure vulnerability exists when the Windows WaasMedic Service improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted application to improperly disclose memory. The security update addresses the vulnerability by correcting how the Windows WaasMedic Service handles memory.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0118
EPSS Percentile 64.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (9)
microsoft/windows_10 1803
microsoft/windows_10 1809
microsoft/windows_10 1903
microsoft/windows_10 1909
microsoft/windows_10 2004
microsoft/windows_server_2016 1903
microsoft/windows_server_2016 1909
microsoft/windows_server_2016 2004
microsoft/windows_server_2019
Published Aug 17, 2020
Tracked Since Feb 18, 2026