CVE-2020-1054
KEVHIGH 7.8EPSS 54.2%
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1143.
- CVSS v3.1
- 7.0 HIGH
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 54.16% chance of exploitation in the next 30 days, 99th percentile
- CISA KEV
- added 2021-11-03
- Published
- 2020-05-21
- Updated
- 2026-08-19
Proof-of-concept exploits (5)
- http://packetstormsecurity.com/files/160515/Microsoft-Windows-DrawIconEx-Local-Privilege-…
- 0xeb-bp/cve-2020-105487★ · 2020-06-17
- Graham382/CVE-2020-10540★ · 2020-10-28
- Iamgublin/CVE-2020-10544★ · 2020-07-19
- KaLendsi/CVE-2020-105420★ · 2020-07-27