7
CVSSv3

CVE-2020-17057

Published: 11/11/2020 Updated: 31/12/2023
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7 | Impact Score: 5.9 | Exploitability Score: 1
VMScore: 642
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Windows Win32k Elevation of Privilege Vulnerability

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows 10 1607

microsoft windows server 2016 -

microsoft windows 10 1803

microsoft windows server 2019 -

microsoft windows 10 1809

microsoft windows server 2016 1903

microsoft windows 10 1903

microsoft windows server 2016 1909

microsoft windows 10 1909

microsoft windows 10 2004

microsoft windows server 2016 2004

microsoft windows 10 20h2

microsoft windows server 2016 20h2

Github Repositories

cve-2020-17057 poc

cve-2020-17057 cve-2020-17057 poc 微软于2020-11-10日发布补丁修补

I wrote this exp based on this blog(blogs360cn/post/CVE-2020-17057%20detail%20and%20exploithtml),But I ended up with only palette objects with dangling data pointer Because of type isolation, I can't get arbitrary R/W primitives by using palettes or bitmap objects,If you have a way to get arbitrary R/W primitives or continue to write this exp,Please c