CVE-2020-1088: Microsoft Windows 10

High severity, CVSS 7.8. EPSS: 0.9% chance of exploitation in the next 30 days.

An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of privilege if an attacker can successfully exploit it. An attacker who successfully exploited the vulnerability could gain greater access to sensitive information and system functionality. To exploit the vulnerability, an attacker could run a specially crafted application. The security update addresses the vulnerability by correcting the way that WER handles and executes files.

Affected products

  • Microsoft Windows 10: affected versions not specified; version 1607 only; version 1709 only; version 1803 only; version 1809 only; version 1903 only; …
  • Microsoft Windows Server 2016: affected versions not specified
  • Microsoft Windows Server 2019: affected versions not specified; version 1803 only; version 1903 only; version 1909 only

Published 2020-05-21. Last modified 2026-08-19.