CVE-2020-1150
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
Summary
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit a malicious webpage. The security update addresses the vulnerability by correcting how Windows Media Foundation handles objects in memory.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Microsoft | Windows 7 | 6.1.0 < publication | affected |
| Microsoft | Windows 7 Service Pack 1 | 6.1.0 < publication | affected |
| Microsoft | Windows Server 2008 R2 Service Pack 1 | 6.1.7601.0 < publication | affected |
| Microsoft | Windows Server 2008 R2 Service Pack 1 (Server Core installation) | 6.1.7601.0 < publication | affected |
Weaknesses
- Remote Code Execution
ADP Enrichment
CVE Program Container
Additional References
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.