CVE-2020-1244
Last modified
CVE-2020-1244 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. A denial of service vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Denial of Service Vulnerability'. This CVE ID is unique from CVE-2020-1120.. EPSS estimates a 3.02% chance of exploitation in the next 30 days.
Description
A denial of service vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Denial of Service Vulnerability'. This CVE ID is unique from CVE-2020-1120.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows 10 | 1809 |
| Microsoft | Windows 10 | 1903 |
| Microsoft | Windows 10 | 1909 |
| Microsoft | Windows 10 | 2004 |
| Microsoft | Windows Server 2016 | 1903 |
| Microsoft | Windows Server 2016 | 1909 |
| Microsoft | Windows Server 2016 | 2004 |
| Microsoft | Windows Server 2019 | All versions |
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1244Patch, Vendor Advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1244Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-1244?
How severe is CVE-2020-1244?
How do I fix CVE-2020-1244?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-1243<p>A denial of service vulnerability exists when Microsoft H…7.8
- CVE-2020-12430An issue was discovered in qemuDomainGetStatsIOThread in qem…6.5
- CVE-2020-12431A Windows privilege change issue was discovered in Splashtop…6.6
- CVE-2020-12432The WOPI API integration for Vereign Collabora CODE through …6.1
- CVE-2020-12438An XSS vulnerability exists in the banners.php page of PHP-F…5.4
- CVE-2020-12439Grin before 3.1.0 allows attackers to adversely affect avail…5.3
- CVE-2020-12440Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2020-12441Denial-of-Service (DoS) in Ivanti Service Manager HEAT Remot…9.8
- CVE-2020-12442Ivanti Avalanche 6.3 allows a SQL injection that is vaguely …9.8
- CVE-2020-12443BigBlueButton before 2.2.6 allows remote attackers to read a…9.8
- CVE-2020-12446The ene.sys driver in G.SKILL Trident Z Lighting Control thr…7.8
- CVE-2020-12447A Local File Inclusion (LFI) issue on Onkyo TX-NR585 1000-00…7.5
Are you affected by CVE-2020-1244?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
