<p>An information disclosure vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system (low-integrity to medium-integrity).</p> <p>This vulnerability by itself does not allow arbitrary code execution; however, it could allow arbitrary code to be run if the attacker uses it in combination with another vulnerability (such as a remote code execution vulnerability or another elevation of privilege vulnerability) that is capable of leveraging the elevated privileges when code execution is attempted.</p> <p>The security update addresses the vulnerability by ensuring splwow64.exe properly handles these calls.</p>
2020-09-11T17:15:14.307
2024-11-21T04:54:22.810
Modified
CVSSv3.1: 5.5 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:N/A:N
8.6
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | microsoft | windows_10 | - | Yes |
| Operating System | microsoft | windows_10 | - | Yes |
| Operating System | microsoft | windows_10 | 1607 | Yes |
| Operating System | microsoft | windows_10 | 1607 | Yes |
| Operating System | microsoft | windows_10 | 1709 | Yes |
| Operating System | microsoft | windows_10 | 1803 | Yes |
| Operating System | microsoft | windows_10 | 1809 | Yes |
| Operating System | microsoft | windows_10 | 1903 | Yes |
| Operating System | microsoft | windows_10 | 1909 | Yes |
| Operating System | microsoft | windows_10 | 2004 | Yes |
| Operating System | microsoft | windows_8.1 | - | Yes |
| Operating System | microsoft | windows_8.1 | - | Yes |
| Operating System | microsoft | windows_rt_8.1 | - | Yes |
| Operating System | microsoft | windows_server_2012 | - | Yes |
| Operating System | microsoft | windows_server_2012 | r2 | Yes |
| Operating System | microsoft | windows_server_2016 | - | Yes |
| Operating System | microsoft | windows_server_2016 | 1903 | Yes |
| Operating System | microsoft | windows_server_2016 | 1909 | Yes |
| Operating System | microsoft | windows_server_2016 | 2004 | Yes |
| Operating System | microsoft | windows_server_2019 | - | Yes |