New Search

Windows Shell Remote Code Execution Vulnerability - CVE-2020-1286

oval:org.cisecurity:def:7778

A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths. An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the current user. If the current user is logged on as an administrator an attacker could take control of the affected system. An attacker could then install programs; view change or delete data; or create new accounts with elevated privileges. Users whose accounts are configured to have fewer privileges on the system could be less impacted than users who operate with administrative privileges. To exploit the vulnerability an attacker must entice a user to open a specially crafted file. In an email attack scenario an attacker could exploit the vulnerability by sending the specially crafted file to the user and then convincing the user to open the file. In a web-based attack scenario an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) that contains a specially crafted file designed to exploit the vulnerability. An attacker would have no way to force a user to visit the website. Instead an attacker would have to convince a user to click a link and open the specially crafted file. This security update addresses the vulnerability by ensuring the Windows Shell properly validates file paths.

Family:
windows
Status:
ACCEPTED
Platform(s):
  • Microsoft Windows 10
  • Microsoft Windows Server 2019
Class:
vulnerability
Reference(s):
  • CVE-2020-1286
  • MSRC-CVE-2020-1286
  • KB4561602
  • KB4561621
  • KB4561608
  • KB4560960
Product(s):