CVE-2020-1273 is an elevation of privilege vulnerability in the Windows Kernel, affecting Windows 10 and Windows Server 2016, where improper handling of memory objects allows an attacker to gain elevated privileges. This vulnerability has a high CVSS score of 7.8, indicating a local attack with low complexity that could lead to high impact on confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, it received some community discussion and media coverage during its disclosure. It is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1903CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1903:*:*:*:*:*:*:* | ||
1909CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1909:*:*:*:*:*:*:* | ||
2004CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:2004:*:*:*:*:*:*:* | ||
1903CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:1903:*:*:*:*:*:*:* | ||
1909CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:1909:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.