CYBER CODE RED

Get real-time updates on Telegram

P3Verified

CVE-2020-1054: windows 10 1507 Version not applicable in the source CPE; +44 more affected products

CVE-2020-1054. CVSS 3.1 base score 7.8 (HIGH, NVD). EPSS 0.54158 (percentile 0.98983), scored 2026-10-06.

Affected technology

windows 10 1507 · Version not applicable in the source CPE
microsoft

windows 10 1607 · Version not applicable in the source CPE
microsoft

windows 10 1709 · Version not applicable in the source CPE
microsoft

windows 10 1803 · Version not applicable in the source CPE
microsoft

windows 10 1809 · Version not applicable in the source CPE
microsoft

windows 10 1903 · Version not applicable in the source CPE
microsoft

windows 10 1909 · Version not applicable in the source CPE
microsoft

windows 7 · Version not applicable in the source CPE
microsoft

windows 8.1 · Version not applicable in the source CPE
microsoft

windows rt 8.1 · Version not applicable in the source CPE
microsoft

windows server 1803 · Version not applicable in the source CPE
microsoft

windows server 1903 · Version not applicable in the source CPE
microsoft

windows server 1909 · Version not applicable in the source CPE
microsoft

windows server 2008 · Version not applicable in the source CPE
microsoft

windows server 2008 · r2 · update sp1
microsoft

windows server 2012 · Version not applicable in the source CPE
microsoft

windows server 2012 · r2
microsoft

windows server 2016 · Version not applicable in the source CPE
microsoft

windows server 2019 · Version not applicable in the source CPE
microsoft

Windows 10 Version 1507 · 10.0.10240.0 to before publication
Microsoft

Windows 10 Version 1607 · 10.0.14393.0 to before publication
Microsoft

Windows 10 Version 1709 · 10.0.0 to before publication
Microsoft

Windows 10 Version 1709 for 32-bit Systems · 10.0.0 to before publication
Microsoft

Windows 10 Version 1803 · 10.0.0 to before publication
Microsoft

Windows 10 Version 1809 · 10.0.17763.0 to before publication
Microsoft

Windows 10 Version 1809 · 10.0.0 to before publication
Microsoft

Windows 10 Version 1903 for 32-bit Systems · 10.0.0 to before publication
Microsoft

Windows 10 Version 1903 for ARM64-based Systems · 10.0.0 to before publication
Microsoft

Windows 10 Version 1903 for x64-based Systems · 10.0.0 to before publication
Microsoft

Windows 10 Version 1909 · 10.0.0 to before publication
Microsoft

Windows 7 · 6.1.0 to before publication
Microsoft

Windows 7 Service Pack 1 · 6.1.0 to before publication
Microsoft

Windows 8.1 · 6.3.0 to before publication
Microsoft

Windows Server 2008 R2 Service Pack 1 · 6.1.7601.0 to before publication
Microsoft

Windows Server 2008 R2 Service Pack 1 (Server Core installation) · 6.1.7601.0 to before publication
Microsoft

Windows Server 2008 Service Pack 2 · 6.0.6003.0 to before publication
Microsoft

Windows Server 2008 Service Pack 2 (Server Core installation) · 6.0.6003.0 to before publication
Microsoft

Windows Server 2012 · 6.2.9200.0 to before publication
Microsoft

Windows Server 2012 (Server Core installation) · 6.2.9200.0 to before publication
Microsoft

Windows Server 2012 R2 · 6.3.9600.0 to before publication
Microsoft

Windows Server 2012 R2 (Server Core installation) · 6.3.9600.0 to before publication
Microsoft

Windows Server 2016 · 10.0.14393.0 to before publication
Microsoft

Windows Server 2016 (Server Core installation) · 10.0.14393.0 to before publication
Microsoft

Windows Server 2019 · 10.0.17763.0 to before publication
Microsoft

Windows Server 2019 (Server Core installation) · 10.0.17763.0 to before publication
Microsoft

Windows Server, version 1803 (Server Core Installation) · 10.0.0 to before publication
Microsoft

Windows Server, version 1903 (Server Core installation) · 10.0.0 to before publication
Microsoft

Windows Server, version 1909 (Server Core installation) · 10.0.0 to before publication
Microsoft

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 3.1): Local · Low privileges required · No user interaction required

Attack conditions (NVD, CVSS 3.1): Local · Low privileges required · No user interaction required

What an attacker can do

An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Vendor/CNA’s CVSS 3.1 assessment (base score 7.0/10) rates confidentiality, integrity and availability impact as high. NVD’s CVSS 3.1 assessment (base score 7.8/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-787
CCR priority
44.7 /100 (P3)
CVSS 3.1
7.8 /10 · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H · NVD
EPSS
0.54158 · percentile 0.98983 · 2026-10-06
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2020-1054.html