VDB
CVE-2020-1579
CVE-2020-1579
PUBLISHED
CVSS 7.800000190734863 HIGH
An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Function Discovery SSDP Provider Elevation of Privilege Vulnerability'.
EPSS 0.40% · 61.1th percentile
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.40%
61.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows 10 Version 1903 for 32-bit Systems | 10.0.0 |
| Microsoft | Windows Server 2016 | 10.0.0 |
| Microsoft | Windows 10 Version 2004 | 10.0.0 |
| Microsoft | Windows Server 2012 R2 | 6.3.0 |
| Microsoft | Windows Server 2008 Service Pack 2 | 6.0.0 |
| Microsoft | Windows 10 Version 1809 | 10.0.0 |
| Microsoft | Windows Server version 2004 | 10.0.0 |
| microsoft | windows_server_2008 | r2 |
| Microsoft | Windows Server, version 1909 (Server Core installation) | 10.0.0 |
| Microsoft | Windows Server 2019 | 10.0.0 |
| microsoft | windows_server_2016 | 2004, 1909, 1903 |
| Microsoft | Windows Server 2016 (Server Core installation) | 10.0.0 |
| Microsoft | Windows 10 Version 1903 for x64-based Systems | 10.0.0 |
| microsoft | windows_7 | |
| Microsoft | Windows Server 2008 Service Pack 2 | 6.0.0 |
| Microsoft | Windows 8.1 | 6.3.0 |
| Microsoft | Windows Server 2008 R2 Service Pack 1 (Server Core installation) | 6.0.0 |
| Microsoft | Windows 10 Version 1909 | 10.0.0 |
| Microsoft | Windows Server 2008 Service Pack 2 (Server Core installation) | 6.0.0 |
| Microsoft | Windows Server 2019 (Server Core installation) | 10.0.0 |
…and 18 more
Exploit Intelligence
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1579 (circl)
- java-sig.yara (github-yara)
- java-sig.yara (github-yara)
- java-sig.yara (github-yara)
- java-sig.yara (github-yara)
- guids_only.yara (github-yara)
- guids_only.yara (github-yara)
- guids_only.yara (github-yara)
- guids_only.yara (github-yara)
- Black-Basta.yar (github-yara)
…and 23 more exploits
Timeline
- Aug 12, 2020 CVE Published
- Sep 17, 2020 PoC Published
- Oct 3, 2020 PoC Published
- Jan 10, 2021 PoC Published
- Apr 14, 2021 EPSS Score
- Jun 22, 2021 PoC Published
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 28, 2022 EPSS Score