CVE-2020-1054: Microsoft Win32k Privilege Escalation Vulnerability
High severity, CVSS 7.0. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 54.2% chance of exploitation in the next 30 days.
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. The update addresses this vulnerability by correcting how the Windows kernel-mode driver handles objects in memory.
Affected products
- Microsoft Windows 10 1507: affected versions not specified
- Microsoft Windows 10 1607: affected versions not specified
- Microsoft Windows 10 1709: affected versions not specified
- Microsoft Windows 10 1803: affected versions not specified
- Microsoft Windows 10 1809: affected versions not specified
- Microsoft Windows 10 1903: affected versions not specified
- Microsoft Windows 10 1909: affected versions not specified
- Microsoft Windows 7: affected versions not specified
- Microsoft Windows 8.1: affected versions not specified
- Microsoft Windows Rt 8.1: affected versions not specified
- Microsoft Windows Server 1803: affected versions not specified
- Microsoft Windows Server 1903: affected versions not specified
- Microsoft Windows Server 1909: affected versions not specified
- Microsoft Windows Server 2008: affected versions not specified; version r2 only
- Microsoft Windows Server 2012: affected versions not specified; version r2 only
- Microsoft Windows Server 2016: affected versions not specified
- Microsoft Windows Server 2019: affected versions not specified
Published 2020-05-21. Last modified 2026-10-08.