CVE-2020-1082 Details
Description
An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of privilege if an attacker can successfully exploit it. An attacker who successfully exploited the vulnerability could gain greater access to sensitive information and system functionality. To exploit the vulnerability, an attacker could run a specially crafted application. The security update addresses the vulnerability by correcting the way that WER handles and executes files.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1082 | CVE | PatchVendor Advisory |
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2020-1082 | CVE | Third Party Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-1082 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| microsoft windows 10 | 1607 1709 1803 1809 1903 1909 |
CPE
Remediation
| |
| microsoft windows server | 1803 |
CPE
Remediation
| |
| microsoft windows server 2016 | 1903 1909 |
CPE
Remediation
| |
| microsoft windows server 2019 | All versions |
CPE
Remediation
| |
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 19, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| May 23, 2022 | CPE Deprecation Remap | [email protected] |
| Apr 27, 2022 | Modified Analysis | [email protected] |
| Jul 21, 2021 | CWE Remap | [email protected] |
| Aug 31, 2020 | CVE Modified | [email protected] |
| May 28, 2020 | Initial Analysis | [email protected] |