mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-31 05:59:31 +02:00
42 lines
3.9 KiB
Markdown
42 lines
3.9 KiB
Markdown
### [CVE-2020-0875](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0875)
|
||

|
||

|
||

|
||

|
||

|
||

|
||

|
||

|
||

|
||

|
||

|
||

|
||
&color=blue)
|
||
&color=blue)
|
||

|
||

|
||
&color=blue)
|
||

|
||
&color=blue)
|
||

|
||

|
||
&color=blue)
|
||
&color=blue)
|
||

|
||

|
||

|
||

|
||
|
||
### Description
|
||
|
||
<p>An information disclosure vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system (low-integrity to medium-integrity).</p><p>This vulnerability by itself does not allow arbitrary code execution; however, it could allow arbitrary code to be run if the attacker uses it in combination with another vulnerability (such as a remote code execution vulnerability or another elevation of privilege vulnerability) that is capable of leveraging the elevated privileges when code execution is attempted.</p><p>The security update addresses the vulnerability by ensuring splwow64.exe properly handles these calls.</p>
|
||
|
||
### POC
|
||
|
||
#### Reference
|
||
No PoCs from references.
|
||
|
||
#### Github
|
||
- https://github.com/404notf0und/CVE-Flow
|
||
|