New Search

Microsoft splwow64 Information Disclosure Vulnerability - CVE-2020-0875

oval:org.cisecurity:def:8324

An information disclosure vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system (low-integrity to medium-integrity). This vulnerability by itself does not allow arbitrary code execution; however it could allow arbitrary code to be run if the attacker uses it in combination with another vulnerability (such as a remote code execution vulnerability or another elevation of privilege vulnerability) that is capable of leveraging the elevated privileges when code execution is attempted. The security update addresses the vulnerability by ensuring splwow64.exe properly handles these calls.

Family:
windows
Status:
ACCEPTED
Platform(s):
  • Microsoft Windows Server 2016
  • Microsoft Windows 10
  • Microsoft Windows Server 2012
  • Microsoft Windows Server 2012 R2
  • Microsoft Windows 8.1
  • Microsoft Windows Server 2019
Class:
vulnerability
Reference(s):
  • CVE-2020-0875
  • MSRC-CVE-2020-0875
  • KB4577048
  • KB4577071
  • KB4577049
  • KB4577015
  • KB4577041
  • KB4577032
  • KB4570333
  • KB4574727
Product(s):