CVE-2020-1537
Last modified
CVE-2020-1537 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. An elevation of privilege vulnerability exists when the Windows Remote Access improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges. To exploit the vulnerability, an attacker would first need code execution on a victim system. EPSS estimates a 0.80% chance of exploitation in the next 30 days.
Description
An elevation of privilege vulnerability exists when the Windows Remote Access improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges. To exploit the vulnerability, an attacker would first need code execution on a victim system. An attacker could then run a specially crafted application. The security update addresses the vulnerability by ensuring the Windows Remote Access properly handles file operations.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Windows 10 | All versions | — |
| Microsoft | Windows 10 | 1607 | — |
| Microsoft | Windows 10 | 1709 | — |
| Microsoft | Windows 10 | 1803 | — |
| Microsoft | Windows 10 | 1809 | — |
| Microsoft | Windows 10 | 1903 | — |
| Microsoft | Windows 10 | 1909 | — |
| Microsoft | Windows 10 | 2004 | — |
| Microsoft | Windows 7 | All versions | Sp1 |
| Microsoft | Windows 8.1 | All versions | — |
| Microsoft | Windows Rt 8.1 | All versions | — |
| Microsoft | Windows Server 2008 | All versions | Sp2 |
| Microsoft | Windows Server 2012 | All versions | — |
| Microsoft | Windows Server 2012 | r2 | — |
| Microsoft | Windows Server 2016 | All versions | — |
| Microsoft | Windows Server 2016 | 1903 | — |
| Microsoft | Windows Server 2016 | 1909 | — |
| Microsoft | Windows Server 2016 | 2004 | — |
| Microsoft | Windows Server 2019 | All versions | — |
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1537Patch, Vendor Advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1537Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-1537?
How severe is CVE-2020-1537?
How do I fix CVE-2020-1537?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-15364The Nexos theme through 1.7 for WordPress allows top-map/?se…6.1
- CVE-2020-15365LibRaw before 0.20-Beta3 has an out-of-bounds write in parse…6.5
- CVE-2020-15366An issue was discovered in ajv.validate() in Ajv (aka Anothe…5.6
- CVE-2020-15367Venki Supravizio BPM 10.1.2 does not limit the number of aut…9.8
- CVE-2020-15368AsrDrv103.sys in the ASRock RGB Driver does not properly res…5.5
- CVE-2020-15369Supportlink CLI in Brocade Fabric OS Versions v8.2.1 through…8.8
- CVE-2020-15370Brocade Fabric OS versions before Brocade Fabric OS v7.4.2g …6.5
- CVE-2020-15371Brocade Fabric OS versions before Brocade Fabric OS v9.0.0, …9.8
- CVE-2020-15372A vulnerability in the command-line interface in Brocade Fab…5.5
- CVE-2020-15373Multiple buffer overflow vulnerabilities in REST API in Broc…9.8
- CVE-2020-15374Rest API in Brocade Fabric OS v8.2.1 through v8.2.1d, and 8.…9.8
- CVE-2020-15375Brocade Fabric OS versions before v9.0.0, v8.2.2c, v8.2.1e, …6.7
Are you affected by CVE-2020-1537?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
