CVE-2020-16923

Description

A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a user would have to open a specially crafted file. The security update addresses the vulnerability by correcting how Microsoft Graphics Components handle objects in memory.

Risk Information

Base Score
7.7
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
EPSS Score
Exploitation Probability
12.686

Associated Vulnerability

VulnerabilityOS Platform
Windows Backup Service Elevation of Privilege Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB4580387) (ESU)Windows
Windows Backup Service Elevation of Privilege Vulnerability for Windows 7 for x64-based Systems (KB4580387) (ESU)Windows
Windows Backup Service Elevation of Privilege Vulnerability for Windows 7 for x86-based Systems (KB4580387) (ESU)Windows
Windows Backup Service Elevation of Privilege Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB4580345) (ESU)Windows
Windows Backup Service Elevation of Privilege Vulnerability for Windows 7 for x86-based Systems (KB4580345) (ESU)Windows
Windows Backup Service Elevation of Privilege Vulnerability for Windows 7 for x64-based Systems (KB4580345) (ESU)Windows
Windows Backup Service Elevation of Privilege Vulnerability for Windows 10 Version 1903 for x86-based Systems (KB4577671)Windows
Windows Backup Service Elevation of Privilege Vulnerability for Windows Server, version 1903 for x64-based Systems (KB4577671)Windows
Windows Backup Service Elevation of Privilege Vulnerability for Windows Server, version 1909 for x64-based Systems (KB4577671)Windows
Windows Backup Service Elevation of Privilege Vulnerability for Windows 10 Version 1909 for x64-based Systems (KB4577671)Windows
Windows Backup Service Elevation of Privilege Vulnerability for Windows 10 Version 1903 for x64-based Systems (KB4577671)Windows
Windows Backup Service Elevation of Privilege Vulnerability for Windows 10 Version 1909 for x86-based Systems (KB4577671)Windows
.NET Framework Information Disclosure Vulnerability for Windows 10 Version 1709 for x86-based Systems (KB4580328)Windows
.NET Framework Information Disclosure Vulnerability for Windows 10 Version 1709 for x64-based Systems (KB4580328)Windows
Group Policy Elevation of Privilege Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB4580358)Windows
Group Policy Elevation of Privilege Vulnerability for Windows 8.1 for x64-based Systems (KB4580358)Windows
Group Policy Elevation of Privilege Vulnerability for Windows 8.1 for x86-based Systems (KB4580358)Windows
Group Policy Elevation of Privilege Vulnerability for Windows 8.1 for x64-based Systems (KB4580347)Windows
Group Policy Elevation of Privilege Vulnerability for Windows 8.1 for x86-based Systems (KB4580347)Windows
Group Policy Elevation of Privilege Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB4580347)Windows
Group Policy Elevation of Privilege Vulnerability for Windows Server 2008 for x64-based Systems (KB4580385) (ESU)Windows
Group Policy Elevation of Privilege Vulnerability for Windows Server 2008 for x86-based Systems (KB4580385) (ESU)Windows
Group Policy Elevation of Privilege Vulnerability for Windows Server 2008 for x64-based Systems (KB4580378) (ESU)Windows
Group Policy Elevation of Privilege Vulnerability for Windows Server 2008 for x86-based Systems (KB4580378) (ESU)Windows
.NET Framework Information Disclosure Vulnerability for Windows 10 Version 1803 for x86-based Systems (KB4580330)Windows
.NET Framework Information Disclosure Vulnerability for Windows 10 Version 1803 for x64-based Systems (KB4580330)Windows
.NET Framework Information Disclosure Vulnerability for Windows Server 2016 for x64-based Systems (KB4580346)Windows
.NET Framework Information Disclosure Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB4580346)Windows
.NET Framework Information Disclosure Vulnerability for Windows 10 Version 1607 for x86-based Systems (KB4580346)Windows
Group Policy Elevation of Privilege Vulnerability for Windows Server 2012 for x64-based Systems (KB4580353)Windows
Group Policy Elevation of Privilege Vulnerability for Windows Server 2012 for x64-based Systems (KB4580382)Windows
Windows Backup Service Elevation of Privilege Vulnerability for Windows 10 Version 1809 for x86-based Systems (KB4577668)Windows
Windows Backup Service Elevation of Privilege Vulnerability for Windows 10 Version 1809 for x64-based Systems (KB4577668)Windows
Windows Backup Service Elevation of Privilege Vulnerability for Windows Server 2019 for x64-based Systems (KB4577668)Windows
.NET Framework Information Disclosure Vulnerability for Windows 10 Version 1507 for x64-based Systems (KB4580327)Windows
.NET Framework Information Disclosure Vulnerability for Windows 10 Version 1507 for x86-based Systems (KB4580327)Windows
Windows Backup Service Elevation of Privilege Vulnerability for Windows 10 Version 2004 for x64-based Systems (KB4579311)Windows
Windows Backup Service Elevation of Privilege Vulnerability for Windows 10 Version 2004 for x86-based Systems (KB4579311)Windows
Windows Backup Service Elevation of Privilege Vulnerability for Windows Server, version 2004 for x64-based Systems (KB4579311)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-299752020-10 Security Only Quality Update for Windows Server 2008 R2 for x64-based Systems (KB4580387) (ESU)
PATCH-299762020-10 Security Only Quality Update for Windows 7 for x64-based Systems (KB4580387) (ESU)
PATCH-299772020-10 Security Only Quality Update for Windows 7 for x86-based Systems (KB4580387) (ESU)
PATCH-299802020-10 Security Monthly Quality Rollup for Windows Server 2008 R2 for x64-based Systems (KB4580345) (ESU)
PATCH-299812020-10 Security Monthly Quality Rollup for Windows 7 for x86-based Systems (KB4580345) (ESU)
PATCH-299822020-10 Security Monthly Quality Rollup for Windows 7 for x64-based Systems (KB4580345) (ESU)
PATCH-300222020-10 Cumulative Update for Windows 10 Version 1903 for x86-based Systems (KB4577671) (CVE-2020-16898)
PATCH-300232020-10 Cumulative Update for Windows Server, version 1903 for x64-based Systems (KB4577671) (CVE-2020-16898)
PATCH-300242020-10 Cumulative Update for Windows Server, version 1909 for x64-based Systems (KB4577671) (CVE-2020-16898)
PATCH-300252020-10 Cumulative Update for Windows 10 Version 1909 for x64-based Systems (KB4577671) (CVE-2020-16898)
PATCH-300262020-10 Cumulative Update for Windows 10 Version 1903 for x64-based Systems (KB4577671) (CVE-2020-16898)
PATCH-300272020-10 Cumulative Update for Windows 10 Version 1909 for x86-based Systems (KB4577671) (CVE-2020-16898)
PATCH-300152020-10 Cumulative Update for Windows 10 Version 1709 for x86-based Systems (KB4580328) (CVE-2020-16898)
PATCH-300162020-10 Cumulative Update for Windows 10 Version 1709 for x64-based Systems (KB4580328) (CVE-2020-16898)
PATCH-299402020-10 Security Only Quality Update for Windows Server 2012 R2 for x64-based Systems (KB4580358)
PATCH-299412020-10 Security Only Quality Update for Windows 8.1 for x64-based Systems (KB4580358)
PATCH-299422020-10 Security Only Quality Update for Windows 8.1 for x86-based Systems (KB4580358)
PATCH-299442020-10 Security Monthly Quality Rollup for Windows 8.1 for x64-based Systems (KB4580347)
PATCH-299452020-10 Security Monthly Quality Rollup for Windows 8.1 for x86-based Systems (KB4580347)
PATCH-299462020-10 Security Monthly Quality Rollup for Windows Server 2012 R2 for x64-based Systems (KB4580347)
PATCH-299782020-10 Security Only Quality Update for Windows Server 2008 for x64-based Systems (KB4580385) (ESU)
PATCH-299792020-10 Security Only Quality Update for Windows Server 2008 for x86-based Systems (KB4580385) (ESU)
PATCH-299832020-10 Security Monthly Quality Rollup for Windows Server 2008 for x64-based Systems (KB4580378) (ESU)
PATCH-299842020-10 Security Monthly Quality Rollup for Windows Server 2008 for x86-based Systems (KB4580378) (ESU)
PATCH-300172020-10 Cumulative Update for Windows 10 Version 1803 for x86-based Systems (KB4580330) (CVE-2020-16898)
PATCH-300182020-10 Cumulative Update for Windows 10 Version 1803 for x64-based Systems (KB4580330) (CVE-2020-16898)
PATCH-300122020-10 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4580346)
PATCH-300132020-10 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB4580346)
PATCH-300142020-10 Cumulative Update for Windows 10 Version 1607 for x86-based Systems (KB4580346)
PATCH-299432020-10 Security Only Quality Update for Windows Server 2012 for x64-based Systems (KB4580353)
PATCH-299472020-10 Security Monthly Quality Rollup for Windows Server 2012 for x64-based Systems (KB4580382)
PATCH-300192020-10 Cumulative Update for Windows 10 Version 1809 for x86-based Systems (KB4577668) (CVE-2020-16898)
PATCH-300202020-10 Cumulative Update for Windows 10 Version 1809 for x64-based Systems (KB4577668) (CVE-2020-16898)
PATCH-300212020-10 Cumulative Update for Windows Server 2019 for x64-based Systems (KB4577668) (CVE-2020-16898)
PATCH-300102020-10 Cumulative Update for Windows 10 Version 1507 for x64-based Systems (KB4580327)
PATCH-300112020-10 Cumulative Update for Windows 10 Version 1507 for x86-based Systems (KB4580327)
PATCH-300282020-10 Cumulative Update for Windows 10 Version 2004 for x64-based Systems (KB4579311) (CVE-2020-16898)
PATCH-300292020-10 Cumulative Update for Windows 10 Version 2004 for x86-based Systems (KB4579311) (CVE-2020-16898)
PATCH-300302020-10 Cumulative Update for Windows Server, version 2004 for x64-based Systems (KB4579311) (CVE-2020-16898)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234