A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit a malicious webpage. The security update addresses the vulnerability by correcting how Windows Media Foundation handles objects in memory.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Msft | microsoft-windows-windows_10-1507-kb4571692microsoft-windows-windows_10-1607-kb4571694microsoft-windows-windows_10-1709-kb4571741microsoft-windows-windows_10-1803-kb4571709microsoft-windows-windows_10-1809-kb4565349microsoft-windows-windows_10-1903-kb4565351microsoft-windows-windows_10-1909-kb4565351microsoft-windows-windows_10-2004-kb4566782microsoft-windows-windows_server_2012_r2-kb4571723microsoft-windows-windows_server_2016-1607-kb4571694microsoft-windows-windows_server_2019-1809-kb4565349msft-kb4565351-4274f60c-bfeb-463c-9754-001689926626msft-kb4565351-79b74e87-e7f9-446e-a595-b7e944725115msft-kb4566782-912b8b41-c59a-4078-bfbf-fb69a4d8c0b3msft-kb4571723-8bf56eb8-928f-4370-9a10-9724b3c610d0msft-kb4571723-c0b15391-31e8-444f-a876-c2f0108bfcc1 | Aug 11, 2020 | Aug 11, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub