Junglewise Threat Intelligence

CVE-2020-0986: Microsoft Windows Kernel Privilege Escalation Vulnerability

CVE-2020-0986 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Windows, Microsoft Windows Server 2012, Microsoft Windows 8.1, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows Server 2016, Microsoft Windows Rt 8.1. Vendors: Microsoft.

Executive brief

An elevation of privilege vulnerability exists in the Microsoft Windows kernel due to improper handling of objects in memory. A local attacker can exploit this to execute code in kernel mode and gain elevated privileges on the system.

Affected products

  • Microsoft Windows 10
  • Microsoft Windows 8.1
  • Microsoft Windows RT 8.1
  • Microsoft Windows Server 2012
  • Microsoft Windows Server 2016
  • Microsoft Windows Server 2019
  • Microsoft Windows Server 1803
  • Microsoft Windows Server 1903
  • Microsoft Windows Server 1909
  • Microsoft Windows Server 2004

Timeline

  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: disclosed

Related threats