CVE-2020-16894
Description
A denial of service vulnerability exists when Windows Network Address Translation (NAT) on a host server fails to properly validate input from a privileged user on a guest operating system. An attacker who successfully exploited the vulnerability could cause the host server to crash. To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application that causes a host machine to crash. The update addresses the vulnerability by modifying how Windows NAT accesses the host.
Risk Information
Base Score
7.0
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H/E:P/RL:O/RC:C
EPSS Score
Exploitation Probability
1.143
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| .NET Framework Information Disclosure Vulnerability for Windows Server 2016 for x64-based Systems (KB4580346) | Windows |
| .NET Framework Information Disclosure Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB4580346) | Windows |
| .NET Framework Information Disclosure Vulnerability for Windows 10 Version 1607 for x86-based Systems (KB4580346) | Windows |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-30012 | 2020-10 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4580346) |
| PATCH-30013 | 2020-10 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB4580346) |
| PATCH-30014 | 2020-10 Cumulative Update for Windows 10 Version 1607 for x86-based Systems (KB4580346) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234