CVE-2020-1393

Description

An elevation of privilege vulnerability exists when the Windows Diagnostics Hub Standard Collector Service fails to properly sanitize input, leading to an unsecure library-loading behavior, aka Windows Diagnostics Hub Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2020-1418.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.285

Associated Vulnerability

VulnerabilityOS Platform
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1809 for x64-based Systems (KB4558998)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1809 for x86-based Systems (KB4558998)Windows
VBScript Remote Code Execution Vulnerability for Windows Server 2019 for x64-based Systems (KB4558998)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1709 for x86-based Systems (KB4565508)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1709 for x64-based Systems (KB4565508)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1803 for x64-based Systems (KB4565489)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1803 for x86-based Systems (KB4565489)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1607 for x86-based Systems (KB4565511)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB4565511)Windows
VBScript Remote Code Execution Vulnerability for Windows Server 2016 for x64-based Systems (KB4565511)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1507 for x86-based Systems (KB4565513)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1507 for x64-based Systems (KB4565513)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1903 for x64-based Systems (KB4565483)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1909 for x64-based Systems (KB4565483)Windows
VBScript Remote Code Execution Vulnerability for Windows Server, version 1903 for x64-based Systems (KB4565483)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1903 for x86-based Systems (KB4565483)Windows
VBScript Remote Code Execution Vulnerability for Windows Server, version 1909 for x64-based Systems (KB4565483)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1909 for x86-based Systems (KB4565483)Windows
VBScript Remote Code Execution Vulnerability for Windows Server, version 2004 for x64-based Systems (KB4565503)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 2004 for x86-based Systems (KB4565503)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 2004 for x64-based Systems (KB4565503)Windows
Vulnerabilities CVE-2020-1393 are affected in Microsoft Visual Studio Community 2017 15.9.24Windows
Vulnerabilities CVE-2020-1393,CVE-2020-1416 are affected in Microsoft Visual Studio Community 2019 16.4.10Windows
Vulnerabilities CVE-2020-1393,CVE-2020-1416 are affected in Microsoft Visual Studio Community 2019 16.6.3Windows
Vulnerabilities CVE-2020-1393 are affected in Microsoft Visual Studio Enterprise 2017 15.9.24Windows
Vulnerabilities CVE-2020-1393,CVE-2020-1416 are affected in Microsoft Visual Studio Enterprise 2019 16.4.10Windows
Vulnerabilities CVE-2020-1393,CVE-2020-1416 are affected in Microsoft Visual Studio Enterprise 2019 16.6.3Windows
Vulnerabilities CVE-2020-1393 are affected in Microsoft Visual Studio Professional 2017 15.9.24Windows
Vulnerabilities CVE-2020-1393,CVE-2020-1416 are affected in Microsoft Visual Studio Professional 2019 16.4.10Windows
Vulnerabilities CVE-2020-1393,CVE-2020-1416 are affected in Microsoft Visual Studio Professional 2019 16.6.3Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-292382020-07 Cumulative Update for Windows 10 Version 1809 for x64-based Systems (KB4558998) (KB4569509) (CVE-2020-1350)
PATCH-292392020-07 Cumulative Update for Windows 10 Version 1809 for x86-based Systems (KB4558998,KB4569509) (CVE-2020-1350)
PATCH-292402020-07 Cumulative Update for Windows Server 2019 for x64-based Systems (KB4558998,KB4569509) (CVE-2020-1350)
PATCH-292462020-07 Cumulative Update for Windows 10 Version 1709 for x86-based Systems (KB4565508)
PATCH-292472020-07 Cumulative Update for Windows 10 Version 1709 for x64-based Systems (KB4565508)
PATCH-292412020-07 Cumulative Update for Windows 10 Version 1803 for x64-based Systems (KB4565489)
PATCH-292422020-07 Cumulative Update for Windows 10 Version 1803 for x86-based Systems (KB4565489)
PATCH-292542020-07 Cumulative Update for Windows 10 Version 1607 for x86-based Systems (KB4565511) (CVE-2020-1350)
PATCH-292552020-07 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB4565511) (CVE-2020-1350)
PATCH-292562020-07 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4565511) (CVE-2020-1350)
PATCH-292572020-07 Cumulative Update for Windows 10 Version 1507 for x86-based Systems (KB4565513)
PATCH-292582020-07 Cumulative Update for Windows 10 Version 1507 for x64-based Systems (KB4565513)
PATCH-292482020-07 Cumulative Update for Windows 10 Version 1903 for x64-based Systems (KB4565483,KB4569509) (CVE-2020-1350)
PATCH-292492020-07 Cumulative Update for Windows 10 Version 1909 for x64-based Systems (KB4565483,KB4569509) (CVE-2020-1350)
PATCH-292502020-07 Cumulative Update for Windows Server, version 1903 for x64-based Systems (KB4565483,KB4569509) (CVE-2020-1350)
PATCH-292512020-07 Cumulative Update for Windows 10 Version 1903 for x86-based Systems (KB4565483,KB4569509) (CVE-2020-1350)
PATCH-292522020-07 Cumulative Update for Windows Server, version 1909 for x64-based Systems (KB4565483,KB4569509) (CVE-2020-1350)
PATCH-292532020-07 Cumulative Update for Windows 10 Version 1909 for x86-based Systems (KB4565483,KB4569509) (CVE-2020-1350)
PATCH-292432020-07 Cumulative Update for Windows Server, version 2004 for x64-based Systems (KB4565503,KB4569509) (CVE-2020-1350)
PATCH-292442020-07 Cumulative Update for Windows 10 Version 2004 for x86-based Systems (KB4565503,KB4569509) (CVE-2020-1350)
PATCH-292452020-07 Cumulative Update for Windows 10 Version 2004 for x64-based Systems (KB4565503,KB4569509) (CVE-2020-1350)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234