A
n elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system. A locally authenticated attacker could exploit this vulnerability by running a specially crafted application. The security update addresses the vulnerability by helping to ensure that the Windows Kernel API properly handles objects in memory.
References
| Link | Resource |
|---|---|
| http://packetstormsecurity.com/files/158938/Microsoft-Windows-CmpDoReDoCreateKey-Arbitrary-Registry-Key-Creation-Privilege-Escalation.html | Third Party Advisory VDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1377 | Patch Vendor Advisory |
| http://packetstormsecurity.com/files/158938/Microsoft-Windows-CmpDoReDoCreateKey-Arbitrary-Registry-Key-Creation-Privilege-Escalation.html | Third Party Advisory VDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1377 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
23 Feb 2026, 18:24
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system. A locally authenticated attacker could exploit this vulnerability by running a specially crafted application. The security update addresses the vulnerability by helping to ensure that the Windows Kernel API properly handles objects in memory. |
21 Nov 2024, 05:10
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://packetstormsecurity.com/files/158938/Microsoft-Windows-CmpDoReDoCreateKey-Arbitrary-Registry-Key-Creation-Privilege-Escalation.html - Third Party Advisory, VDB Entry | |
| References | () https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1377 - Patch, Vendor Advisory |
Information
Published : 2020-08-17 19:15
Updated : 2026-02-23 18:24
NVD link : CVE-2020-1377
Mitre link : CVE-2020-1377
CVE.ORG link : CVE-2020-1377
JSON object : View
Products Affected
CWE