CVE-2020-1459: Microsoft Windows 10
High severity, CVSS 7.5. EPSS: 4.5% chance of exploitation in the next 30 days.
An information disclosure vulnerability exists on ARM implementations that use speculative execution in control flow via a side-channel analysis, aka "straight-line speculation." To exploit this vulnerability, an attacker with local privileges would need to run a specially crafted application. The security update addresses the vulnerability by bypassing the speculative execution.
Affected products
- Microsoft Windows 10: version 1809 only; version 1903 only; version 1909 only; version 2004 only
Published 2020-08-17. Last modified 2026-06-17.