CVE-2020-1459
Published: Aug 17, 2020
Modified: Aug 4, 2024
CVSS v3.1
7.5
Description
An information disclosure vulnerability exists on ARM implementations that use speculative execution in control flow via a side-channel analysis, aka "straight-line speculation." To exploit this vulnerability, an attacker with local privileges would need to run a specially crafted application. The security update addresses the vulnerability by bypassing the speculative execution.
| Vendor | Product | Versions |
|---|---|---|
Microsoft | Windows 10 Version 1809 | affected 10.0.0 - < publication |
Microsoft | Windows 10 Version 1909 | affected 10.0.0 - < publication |
Microsoft | Windows 10 Version 1903 for ARM64-based Systems | affected 10.0.0 - < publication |
Microsoft | Windows 10 Version 2004 | affected 10.0.0 - < publication |
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now