CVE-2020-0997 is a remote code execution vulnerability in the Windows Camera Codec Pack affecting Microsoft Windows 10, Windows Server 2016, and Windows Server 2019. It carries a CVSS score of 7.8 (HIGH) due to its potential for an attacker to run arbitrary code in the context of the current user, leading to full system compromise if the user has administrative rights. Exploitation requires user interaction, typically by opening a specially crafted file received via email or downloaded from a malicious website. While the vulnerability has a high FAUCET Risk Score of 75/100 and some community discussion, there is no evidence of active exploitation, nor is public exploit code available in Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:x64:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:x86:* | ||
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:x64:* | ||
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:x86:* | ||
1709CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.