CVE-2020-1520

Description

A remote code execution vulnerability exists when the Windows Font Driver Host improperly handles memory.An attacker who successfully exploited the vulnerability would gain execution on a victim system.The security update addresses the vulnerability by correcting how the Windows Font Driver Host handles memory.

Risk Information

Base Score
7.7
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
EPSS Score
Exploitation Probability
0.376

Associated Vulnerability

VulnerabilityOS Platform
Netlogon Elevation of Privilege Vulnerability for Windows 8.1 for x64-based Systems (KB4571723)Windows
Netlogon Elevation of Privilege Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB4571723)Windows
Netlogon Elevation of Privilege Vulnerability for Windows 8.1 for x86-based Systems (KB4571723)Windows
Windows GDI Elevation of Privilege Vulnerability for Windows Server 2012 for x64-based Systems (KB4571702)Windows
Netlogon Elevation of Privilege Vulnerability for Windows Server 2012 for x64-based Systems (KB4571736)Windows
Netlogon Elevation of Privilege Vulnerability for Windows 10 Version 2004 for x86-based Systems (KB4566782)Windows
Netlogon Elevation of Privilege Vulnerability for Windows Server, version 2004 for x64-based Systems (KB4566782)Windows
Netlogon Elevation of Privilege Vulnerability for Windows 10 Version 2004 for x64-based Systems (KB4566782)Windows
Windows GDI Elevation of Privilege Vulnerability for Windows 10 Version 1709 for x86-based Systems (KB4571741)Windows
Windows GDI Elevation of Privilege Vulnerability for Windows 10 Version 1709 for x64-based Systems (KB4571741)Windows
Netlogon Elevation of Privilege Vulnerability for Windows 10 Version 1809 for x86-based Systems (KB4565349)Windows
Netlogon Elevation of Privilege Vulnerability for Windows 10 Version 1809 for x64-based Systems (KB4565349)Windows
Netlogon Elevation of Privilege Vulnerability for Windows Server 2019 for x64-based Systems (KB4565349)Windows
Netlogon Elevation of Privilege Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB4571694)Windows
Netlogon Elevation of Privilege Vulnerability for Windows 10 Version 1607 for x86-based Systems (KB4571694)Windows
Netlogon Elevation of Privilege Vulnerability for Windows Server 2016 for x64-based Systems (KB4571694)Windows
Netlogon Elevation of Privilege Vulnerability for Windows 8.1 for x64-based Systems (KB4571703)Windows
Netlogon Elevation of Privilege Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB4571703)Windows
Netlogon Elevation of Privilege Vulnerability for Windows 8.1 for x86-based Systems (KB4571703)Windows
Windows GDI Elevation of Privilege Vulnerability for Windows 10 Version 1803 for x64-based Systems (KB4571709)Windows
Windows GDI Elevation of Privilege Vulnerability for Windows 10 Version 1803 for x86-based Systems (KB4571709)Windows
Windows GDI Elevation of Privilege Vulnerability for Windows 10 Version 1507 for x64-based Systems (KB4571692)Windows
Windows GDI Elevation of Privilege Vulnerability for Windows 10 Version 1507 for x86-based Systems (KB4571692)Windows
Netlogon Elevation of Privilege Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB4571719) (ESU)Windows
Netlogon Elevation of Privilege Vulnerability for Windows 7 for x86-based Systems (KB4571719) (ESU)Windows
Netlogon Elevation of Privilege Vulnerability for Windows 7 for x64-based Systems (KB4571719) (ESU)Windows
Netlogon Elevation of Privilege Vulnerability for Windows 7 for x64-based Systems (KB4571729) (ESU)Windows
Netlogon Elevation of Privilege Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB4571729) (ESU)Windows
Netlogon Elevation of Privilege Vulnerability for Windows 7 for x86-based Systems (KB4571729) (ESU)Windows
Netlogon Elevation of Privilege Vulnerability for Windows 10 Version 1909 for x64-based Systems (KB4565351)Windows
Netlogon Elevation of Privilege Vulnerability for Windows 10 Version 1903 for x64-based Systems (KB4565351)Windows
Netlogon Elevation of Privilege Vulnerability for Windows Server, version 1903 for x64-based Systems (KB4565351)Windows
Netlogon Elevation of Privilege Vulnerability for Windows 10 Version 1909 for x86-based Systems (KB4565351)Windows
Netlogon Elevation of Privilege Vulnerability for Windows Server, version 1909 for x64-based Systems (KB4565351)Windows
Netlogon Elevation of Privilege Vulnerability for Windows 10 Version 1903 for x86-based Systems (KB4565351)Windows
Windows GDI Elevation of Privilege Vulnerability for Windows Server 2008 for x86-based Systems (KB4571746) (ESU)Windows
Windows GDI Elevation of Privilege Vulnerability for Windows Server 2008 for x64-based Systems (KB4571746) (ESU)Windows
Windows GDI Elevation of Privilege Vulnerability for Windows Server 2008 for x86-based Systems (KB4571730) (ESU)Windows
Windows GDI Elevation of Privilege Vulnerability for Windows Server 2008 for x64-based Systems (KB4571730) (ESU)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-294722020-08 Security Only Quality Update for Windows 8.1 for x64-based Systems (KB4571723) (CVE-2020-1464) (CVE-2020-1472)
PATCH-294732020-08 Security Only Quality Update for Windows Server 2012 R2 for x64-based Systems (KB4571723) (CVE-2020-1464) (CVE-2020-1472)
PATCH-294742020-08 Security Only Quality Update for Windows 8.1 for x86-based Systems (KB4571723) (CVE-2020-1464) (CVE-2020-1472)
PATCH-294752020-08 Security Only Quality Update for Windows Server 2012 for x64-based Systems (KB4571702) (CVE-2020-1464) (CVE-2020-1472)
PATCH-294792020-08 Security Monthly Quality Rollup for Windows Server 2012 for x64-based Systems (KB4571736) (CVE-2020-1464) (CVE-2020-1380) (CVE-2020-1472)
PATCH-295022020-08 Cumulative Update for Windows 10 Version 2004 for x86-based Systems (KB4566782) (CVE-2020-1464) (CVE-2020-1380) (CVE-2020-1472)
PATCH-295032020-08 Cumulative Update for Windows Server, version 2004 for x64-based Systems (KB4566782) (CVE-2020-1464) (CVE-2020-1380) (CVE-2020-1472)
PATCH-295042020-08 Cumulative Update for Windows 10 Version 2004 for x64-based Systems (KB4566782) (CVE-2020-1464) (CVE-2020-1380) (CVE-2020-1472)
PATCH-294982020-08 Cumulative Update for Windows 10 Version 1709 for x86-based Systems (KB4571741) (CVE-2020-1464) (CVE-2020-1380)
PATCH-294992020-08 Cumulative Update for Windows 10 Version 1709 for x64-based Systems (KB4571741) (CVE-2020-1464) (CVE-2020-1380)
PATCH-294952020-08 Cumulative Update for Windows 10 Version 1809 for x86-based Systems (KB4565349) (CVE-2020-1464) (CVE-2020-1380) (CVE-2020-1472)
PATCH-294962020-08 Cumulative Update for Windows 10 Version 1809 for x64-based Systems (KB4565349) (CVE-2020-1464) (CVE-2020-1380) (CVE-2020-1472)
PATCH-294972020-08 Cumulative Update for Windows Server 2019 for x64-based Systems (KB4565349) (CVE-2020-1464) (CVE-2020-1380) (CVE-2020-1472)
PATCH-295052020-08 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB4571694) (CVE-2020-1464) (CVE-2020-1380) (CVE-2020-1472)
PATCH-295062020-08 Cumulative Update for Windows 10 Version 1607 for x86-based Systems (KB4571694) (CVE-2020-1464) (CVE-2020-1380) (CVE-2020-1472)
PATCH-295072020-08 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4571694) (CVE-2020-1464) (CVE-2020-1380) (CVE-2020-1472)
PATCH-294762020-08 Security Monthly Quality Rollup for Windows 8.1 for x64-based Systems (KB4571703) (CVE-2020-1464) (CVE-2020-1380) (CVE-2020-1472)
PATCH-294772020-08 Security Monthly Quality Rollup for Windows Server 2012 R2 for x64-based Systems (KB4571703) (CVE-2020-1464) (CVE-2020-1380) (CVE-2020-1472)
PATCH-294782020-08 Security Monthly Quality Rollup for Windows 8.1 for x86-based Systems (KB4571703) (CVE-2020-1464) (CVE-2020-1380) (CVE-2020-1472)
PATCH-295002020-08 Cumulative Update for Windows 10 Version 1803 for x64-based Systems (KB4571709) (CVE-2020-1464) (CVE-2020-1380)
PATCH-295012020-08 Cumulative Update for Windows 10 Version 1803 for x86-based Systems (KB4571709) (CVE-2020-1464) (CVE-2020-1380)
PATCH-295082020-08 Cumulative Update for Windows 10 Version 1507 for x64-based Systems (KB4571692) (CVE-2020-1464) (CVE-2020-1380)
PATCH-295092020-08 Cumulative Update for Windows 10 Version 1507 for x86-based Systems (KB4571692) (CVE-2020-1464) (CVE-2020-1380)
PATCH-295102020-08 Security Only Quality Update for Windows Server 2008 R2 for x64-based Systems (KB4571719) (ESU) (CVE-2020-1464) (CVE-2020-1472)
PATCH-295112020-08 Security Only Quality Update for Windows 7 for x86-based Systems (KB4571719) (ESU) (CVE-2020-1464) (CVE-2020-1472)
PATCH-295122020-08 Security Only Quality Update for Windows 7 for x64-based Systems (KB4571719) (ESU) (CVE-2020-1464) (CVE-2020-1472)
PATCH-295152020-08 Security Monthly Quality Rollup for Windows 7 for x64-based Systems (KB4571729) (ESU) (CVE-2020-1464) (CVE-2020-1380) (CVE-2020-1472)
PATCH-295162020-08 Security Monthly Quality Rollup for Windows Server 2008 R2 for x64-based Systems (KB4571729) (ESU) (CVE-2020-1464) (CVE-2020-1380) (CVE-2020-1472)
PATCH-295172020-08 Security Monthly Quality Rollup for Windows 7 for x86-based Systems (KB4571729) (ESU) (CVE-2020-1464) (CVE-2020-1380) (CVE-2020-1472)
PATCH-294892020-08 Cumulative Update for Windows 10 Version 1909 for x64-based Systems (KB4565351) (CVE-2020-1464) (CVE-2020-1380) (CVE-2020-1472)
PATCH-294902020-08 Cumulative Update for Windows 10 Version 1903 for x64-based Systems (KB4565351) (CVE-2020-1464) (CVE-2020-1380) (CVE-2020-1472)
PATCH-294912020-08 Cumulative Update for Windows Server, version 1903 for x64-based Systems (KB4565351) (CVE-2020-1464) (CVE-2020-1380) (CVE-2020-1472)
PATCH-294922020-08 Cumulative Update for Windows 10 Version 1909 for x86-based Systems (KB4565351) (CVE-2020-1464) (CVE-2020-1380) (CVE-2020-1472)
PATCH-294932020-08 Cumulative Update for Windows Server, version 1909 for x64-based Systems (KB4565351) (CVE-2020-1464) (CVE-2020-1380) (CVE-2020-1472)
PATCH-294942020-08 Cumulative Update for Windows 10 Version 1903 for x86-based Systems (KB4565351) (CVE-2020-1464) (CVE-2020-1380) (CVE-2020-1472)
PATCH-295132020-08 Security Only Quality Update for Windows Server 2008 for x86-based Systems (KB4571746) (ESU) (CVE-2020-1464)
PATCH-295142020-08 Security Only Quality Update for Windows Server 2008 for x64-based Systems (KB4571746) (ESU) (CVE-2020-1464)
PATCH-295182020-08 Security Monthly Quality Rollup for Windows Server 2008 for x86-based Systems (KB4571730) (ESU) (CVE-2020-1464)
PATCH-295192020-08 Security Monthly Quality Rollup for Windows Server 2008 for x64-based Systems (KB4571730) (ESU) (CVE-2020-1464)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234