CVE-2020-1389

Description

An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka Windows Kernel Information Disclosure Vulnerability. This CVE ID is unique from CVE-2020-1367, CVE-2020-1419, CVE-2020-1426.

Risk Information

Base Score
5.4
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C
EPSS Score
Exploitation Probability
0.407

Associated Vulnerability

VulnerabilityOS Platform
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1809 for x64-based Systems (KB4558998)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1809 for x86-based Systems (KB4558998)Windows
VBScript Remote Code Execution Vulnerability for Windows Server 2019 for x64-based Systems (KB4558998)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1709 for x86-based Systems (KB4565508)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1709 for x64-based Systems (KB4565508)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1803 for x64-based Systems (KB4565489)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1803 for x86-based Systems (KB4565489)Windows
VBScript Remote Code Execution Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB4565524)(ESU)Windows
VBScript Remote Code Execution Vulnerability for Windows 7 for x86-based Systems (KB4565524)(ESU)Windows
VBScript Remote Code Execution Vulnerability for Windows 7 for x64-based Systems (KB4565524) (ESU)Windows
Jet Database Engine Remote Code Execution Vulnerability for Windows 7 for x86-based Systems (KB4565539) (ESU)Windows
Jet Database Engine Remote Code Execution Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB4565539) (ESU)Windows
Jet Database Engine Remote Code Execution Vulnerability for Windows 7 for x64-based Systems (KB4565539) (ESU)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1607 for x86-based Systems (KB4565511)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB4565511)Windows
VBScript Remote Code Execution Vulnerability for Windows Server 2016 for x64-based Systems (KB4565511)Windows
VBScript Remote Code Execution Vulnerability for Windows 8.1 for x86-based Systems (KB4565541)Windows
VBScript Remote Code Execution Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB4565541)Windows
VBScript Remote Code Execution Vulnerability for Windows 8.1 for x64-based Systems (KB4565541)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1507 for x86-based Systems (KB4565513)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1507 for x64-based Systems (KB4565513)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1903 for x64-based Systems (KB4565483)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1909 for x64-based Systems (KB4565483)Windows
VBScript Remote Code Execution Vulnerability for Windows Server, version 1903 for x64-based Systems (KB4565483)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1903 for x86-based Systems (KB4565483)Windows
VBScript Remote Code Execution Vulnerability for Windows Server, version 1909 for x64-based Systems (KB4565483)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1909 for x86-based Systems (KB4565483)Windows
Jet Database Engine Remote Code Execution Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB4565540)Windows
Jet Database Engine Remote Code Execution Vulnerability for Windows 8.1 for x86-based Systems (KB4565540)Windows
Jet Database Engine Remote Code Execution Vulnerability for Windows 8.1 for x64-based Systems (KB4565540)Windows
VBScript Remote Code Execution Vulnerability for Windows Server 2008 for x86-based Systems (KB4565536) (ESU)Windows
VBScript Remote Code Execution Vulnerability for Windows Server 2008 for x64-based Systems (KB4565536) (ESU)Windows
Jet Database Engine Remote Code Execution Vulnerability for Windows Server 2008 for x86-based Systems (KB4565529) (ESU)Windows
Jet Database Engine Remote Code Execution Vulnerability for Windows Server 2008 for x64-based Systems (KB4565529) (ESU)Windows
Jet Database Engine Remote Code Execution Vulnerability for Windows Server 2012 for x64-based Systems (KB4565535)Windows
VBScript Remote Code Execution Vulnerability for Windows Server 2012 for x64-based Systems (KB4565537)Windows
VBScript Remote Code Execution Vulnerability for Windows Server, version 2004 for x64-based Systems (KB4565503)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 2004 for x86-based Systems (KB4565503)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 2004 for x64-based Systems (KB4565503)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-292382020-07 Cumulative Update for Windows 10 Version 1809 for x64-based Systems (KB4558998) (KB4569509) (CVE-2020-1350)
PATCH-292392020-07 Cumulative Update for Windows 10 Version 1809 for x86-based Systems (KB4558998,KB4569509) (CVE-2020-1350)
PATCH-292402020-07 Cumulative Update for Windows Server 2019 for x64-based Systems (KB4558998,KB4569509) (CVE-2020-1350)
PATCH-292462020-07 Cumulative Update for Windows 10 Version 1709 for x86-based Systems (KB4565508)
PATCH-292472020-07 Cumulative Update for Windows 10 Version 1709 for x64-based Systems (KB4565508)
PATCH-292412020-07 Cumulative Update for Windows 10 Version 1803 for x64-based Systems (KB4565489)
PATCH-292422020-07 Cumulative Update for Windows 10 Version 1803 for x86-based Systems (KB4565489)
PATCH-292712020-07 Security Monthly Quality Rollup for Windows Server 2008 R2 for x64-based Systems (KB4565524,KB4569509) (CVE-2020-1350) (ESU)
PATCH-292722020-07 Security Monthly Quality Rollup for Windows 7 for x86-based Systems (KB4565524,KB4569509) (CVE-2020-1350) (ESU)
PATCH-292732020-07 Security Monthly Quality Rollup for Windows 7 for x64-based Systems (KB4565524,KB4569509) (CVE-2020-1350) (ESU)
PATCH-292752020-07 Security Only Quality Update for Windows 7 for x86-based Systems (KB4565539,KB4569509) (CVE-2020-1350) (ESU)
PATCH-292762020-07 Security Only Quality Update for Windows Server 2008 R2 for x64-based Systems (KB4565539,KB4569509) (CVE-2020-1350) (ESU)
PATCH-292772020-07 Security Only Quality Update for Windows 7 for x64-based Systems (KB4565539,KB4569509) (CVE-2020-1350) (ESU)
PATCH-292542020-07 Cumulative Update for Windows 10 Version 1607 for x86-based Systems (KB4565511) (CVE-2020-1350)
PATCH-292552020-07 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB4565511) (CVE-2020-1350)
PATCH-292562020-07 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4565511) (CVE-2020-1350)
PATCH-292682020-07 Security Monthly Quality Rollup for Windows 8.1 for x86-based Systems (KB4565541,KB4569509) (CVE-2020-1350)
PATCH-292692020-07 Security Monthly Quality Rollup for Windows Server 2012 R2 for x64-based Systems (KB4565541,KB4569509) (CVE-2020-1350)
PATCH-292702020-07 Security Monthly Quality Rollup for Windows 8.1 for x64-based Systems (KB4565541,KB4569509) (CVE-2020-1350)
PATCH-292572020-07 Cumulative Update for Windows 10 Version 1507 for x86-based Systems (KB4565513)
PATCH-292582020-07 Cumulative Update for Windows 10 Version 1507 for x64-based Systems (KB4565513)
PATCH-292482020-07 Cumulative Update for Windows 10 Version 1903 for x64-based Systems (KB4565483,KB4569509) (CVE-2020-1350)
PATCH-292492020-07 Cumulative Update for Windows 10 Version 1909 for x64-based Systems (KB4565483,KB4569509) (CVE-2020-1350)
PATCH-292502020-07 Cumulative Update for Windows Server, version 1903 for x64-based Systems (KB4565483,KB4569509) (CVE-2020-1350)
PATCH-292512020-07 Cumulative Update for Windows 10 Version 1903 for x86-based Systems (KB4565483,KB4569509) (CVE-2020-1350)
PATCH-292522020-07 Cumulative Update for Windows Server, version 1909 for x64-based Systems (KB4565483,KB4569509) (CVE-2020-1350)
PATCH-292532020-07 Cumulative Update for Windows 10 Version 1909 for x86-based Systems (KB4565483,KB4569509) (CVE-2020-1350)
PATCH-292342020-07 Security Only Quality Update for Windows Server 2012 R2 for x64-based Systems (KB4565540,KB4569509) (CVE-2020-1350)
PATCH-292352020-07 Security Only Quality Update for Windows 8.1 for x86-based Systems (KB4565540,KB4569509) (CVE-2020-1350)
PATCH-292362020-07 Security Only Quality Update for Windows 8.1 for x64-based Systems (KB4565540,KB4569509) (CVE-2020-1350)
PATCH-292782020-07 Security Monthly Quality Rollup for Windows Server 2008 for x86-based Systems (KB4565536,KB4569509) (CVE-2020-1350) (ESU)
PATCH-292792020-07 Security Monthly Quality Rollup for Windows Server 2008 for x64-based Systems (KB4565536,KB4569509) (CVE-2020-1350) (ESU)
PATCH-292802020-07 Security Only Quality Update for Windows Server 2008 for x86-based Systems (KB4565529,KB4569509) (CVE-2020-1350) (ESU)
PATCH-292812020-07 Security Only Quality Update for Windows Server 2008 for x64-based Systems (KB4565529,KB4569509) (CVE-2020-1350) (ESU)
PATCH-292372020-07 Security Only Quality Update for Windows Server 2012 for x64-based Systems (KB4565535,KB4569509) (CVE-2020-1350)
PATCH-292742020-07 Security Monthly Quality Rollup for Windows Server 2012 for x64-based Systems (KB4565537,KB4569509) (CVE-2020-1350)
PATCH-292432020-07 Cumulative Update for Windows Server, version 2004 for x64-based Systems (KB4565503,KB4569509) (CVE-2020-1350)
PATCH-292442020-07 Cumulative Update for Windows 10 Version 2004 for x86-based Systems (KB4565503,KB4569509) (CVE-2020-1350)
PATCH-292452020-07 Cumulative Update for Windows 10 Version 2004 for x64-based Systems (KB4565503,KB4569509) (CVE-2020-1350)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234