CVE-2020-1084: Microsoft Windows 10

Medium severity, CVSS 5.5. EPSS: 1.1% chance of exploitation in the next 30 days.

A Denial Of Service vulnerability exists when Connected User Experiences and Telemetry Service fails to validate certain function values. An attacker who successfully exploited this vulnerability could deny dependent security feature functionality. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The security update addresses the vulnerability by correcting how the Connected User Experiences and Telemetry Service validates certain function values.

Affected products

  • Microsoft Windows 10: affected versions not specified; version 1607 only; version 1709 only; version 1803 only; version 1809 only; version 1903 only; …
  • Microsoft Windows Server 2016: affected versions not specified
  • Microsoft Windows Server 2019: affected versions not specified

Published 2020-05-21. Last modified 2026-08-19.