CVE-2020-17136 is an Elevation of Privilege vulnerability in the Windows Cloud Files Mini Filter Driver, affecting Windows 10, Server 2016, and Server 2019. It carries a high CVSS score of 7.8, indicating that a local, low-privileged attacker can achieve full compromise (confidentiality, integrity, availability) with low attack complexity. While not currently on CISA's KEV catalog, a Metasploit module exists for a related vulnerability (CVE-2020-1170), and it has garnered significant community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
20h2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:arm64:* | ||
20h2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:x64:* | ||
20h2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:20h2:*:*:*:*:*:x86:* | ||
1803CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:arm64:* | ||
1803CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:x64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.