CVE-2020-1421
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 74.5%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Code Execution Vulnerability'.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 74.50% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-843
- Affected
- microsoft/windows 10 · microsoft/windows server 2016 · microsoft/windows server 2019
- Source
- secure@microsoft.com
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1421Patch, Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-923/Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1421Patch, Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-923/Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.