SARA / Free Tools / CVE / CVE-2020-1143

CVE-2020-1143 — An elevation of privilege vulnerability exists in Windows when the Windows kerne

An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1054.

CVSS
EPSS
6.00% (top 81.20%)
CWE
Published
2020-05-21T22:53:22.000Z
Last modified
2024-08-04T06:25:01.202Z
CVSS vector

01What is this vulnerability?

An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1054.

02Affected products

VendorProductVersions
MicrosoftWindows10 Version 1803 for 32-bit Systems, 10 Version 1803 for x64-based Systems, 10 Version 1803 for ARM64-based Systems, 10 Version 1809 for 32-bit Systems, 10 Version 1809 for x64-based Systems, 10 Version 1809 for ARM64-based Systems, 10 Version 1709 for 32-bit Systems, 10 Version 1709 for x64-based Systems, 10 Version 1709 for ARM64-based Systems, 10 for 32-bit Systems, 10 for x64-based Systems, 10 Version 1607 for 32-bit Systems, 10 Version 1607 for x64-based Systems, 7 for 32-bit Systems Service Pack 1, 7 for x64-based Systems Service Pack 1, 8.1 for 32-bit systems, 8.1 for x64-based systems, RT 8.1
MicrosoftWindows Serverversion 1803 (Core Installation), 2019, 2019 (Core installation), 2016, 2016 (Core installation), 2008 for 32-bit Systems Service Pack 2, 2008 for 32-bit Systems Service Pack 2 (Core installation), 2008 for Itanium-Based Systems Service Pack 2, 2008 for x64-based Systems Service Pack 2, 2008 for x64-based Systems Service Pack 2 (Core installation), 2008 R2 for Itanium-Based Systems Service Pack 1, 2008 R2 for x64-based Systems Service Pack 1, 2008 R2 for x64-based Systems Service Pack 1 (Core installation), 2012, 2012 (Core installation), 2012 R2, 2012 R2 (Core installation)
MicrosoftWindows 10 Version 1909 for 32bit Systems — unspecified
MicrosoftWindows 10 Version 1909 for x64based Systems — unspecified
MicrosoftWindows 10 Version 1909 for ARM64based Systems — unspecified
MicrosoftWindows Server, version 1909 (Server Core installation)unspecified
MicrosoftWindows 10 Version 1903 for 32bit Systems — unspecified
MicrosoftWindows 10 Version 1903 for x64based Systems — unspecified
MicrosoftWindows 10 Version 1903 for ARM64based Systems — unspecified
MicrosoftWindows Server, version 1903 (Server Core installation)unspecified

03Active exploitation status

Not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog. EPSS is the best forward-looking signal — see the EPSS row above.

04Recommended remediation

05Technical details

For the full vendor write-up, exploit chains, and reference implementations, see the references list in section 09.

06Detection signatures

Open the Sigma generator with a pre-filled prompt for this CVE to draft a starting detection in your stack of choice:

Open in Sigma generator →

07Related CVEs

CVE-2020-1054
Cited in vendor advisory

08Timeline

09References

Want this in your SOAR or SIEM?
SARA's API returns EPSS, CVSS, KEV, and an analyst-grade summary in one call.
Read the API reference →