Get real-time updates on Telegram
CVE-2020-1054: windows 10 1507 Version not applicable in the source CPE; +44 more affected products
CVE-2020-1054. CVSS 3.1 base score 7.8 (HIGH, NVD). EPSS 0.54158 (percentile 0.98983), scored 2026-10-06.
Affected technology
windows 10 1507 · Version not applicable in the source CPE
microsoft
windows 10 1607 · Version not applicable in the source CPE
microsoft
windows 10 1709 · Version not applicable in the source CPE
microsoft
windows 10 1803 · Version not applicable in the source CPE
microsoft
windows 10 1809 · Version not applicable in the source CPE
microsoft
windows 10 1903 · Version not applicable in the source CPE
microsoft
windows 10 1909 · Version not applicable in the source CPE
microsoft
windows 7 · Version not applicable in the source CPE
microsoft
windows 8.1 · Version not applicable in the source CPE
microsoft
windows rt 8.1 · Version not applicable in the source CPE
microsoft
windows server 1803 · Version not applicable in the source CPE
microsoft
windows server 1903 · Version not applicable in the source CPE
microsoft
windows server 1909 · Version not applicable in the source CPE
microsoft
windows server 2008 · Version not applicable in the source CPE
microsoft
windows server 2008 · r2 · update sp1
microsoft
windows server 2012 · Version not applicable in the source CPE
microsoft
windows server 2012 · r2
microsoft
windows server 2016 · Version not applicable in the source CPE
microsoft
windows server 2019 · Version not applicable in the source CPE
microsoft
Windows 10 Version 1507 · 10.0.10240.0 to before publication
Microsoft
Windows 10 Version 1607 · 10.0.14393.0 to before publication
Microsoft
Windows 10 Version 1709 · 10.0.0 to before publication
Microsoft
Windows 10 Version 1709 for 32-bit Systems · 10.0.0 to before publication
Microsoft
Windows 10 Version 1803 · 10.0.0 to before publication
Microsoft
Windows 10 Version 1809 · 10.0.17763.0 to before publication
Microsoft
Windows 10 Version 1809 · 10.0.0 to before publication
Microsoft
Windows 10 Version 1903 for 32-bit Systems · 10.0.0 to before publication
Microsoft
Windows 10 Version 1903 for ARM64-based Systems · 10.0.0 to before publication
Microsoft
Windows 10 Version 1903 for x64-based Systems · 10.0.0 to before publication
Microsoft
Windows 10 Version 1909 · 10.0.0 to before publication
Microsoft
Windows 7 · 6.1.0 to before publication
Microsoft
Windows 7 Service Pack 1 · 6.1.0 to before publication
Microsoft
Windows 8.1 · 6.3.0 to before publication
Microsoft
Windows Server 2008 R2 Service Pack 1 · 6.1.7601.0 to before publication
Microsoft
Windows Server 2008 R2 Service Pack 1 (Server Core installation) · 6.1.7601.0 to before publication
Microsoft
Windows Server 2008 Service Pack 2 · 6.0.6003.0 to before publication
Microsoft
Windows Server 2008 Service Pack 2 (Server Core installation) · 6.0.6003.0 to before publication
Microsoft
Windows Server 2012 · 6.2.9200.0 to before publication
Microsoft
Windows Server 2012 (Server Core installation) · 6.2.9200.0 to before publication
Microsoft
Windows Server 2012 R2 · 6.3.9600.0 to before publication
Microsoft
Windows Server 2012 R2 (Server Core installation) · 6.3.9600.0 to before publication
Microsoft
Windows Server 2016 · 10.0.14393.0 to before publication
Microsoft
Windows Server 2016 (Server Core installation) · 10.0.14393.0 to before publication
Microsoft
Windows Server 2019 · 10.0.17763.0 to before publication
Microsoft
Windows Server 2019 (Server Core installation) · 10.0.17763.0 to before publication
Microsoft
Windows Server, version 1803 (Server Core Installation) · 10.0.0 to before publication
Microsoft
Windows Server, version 1903 (Server Core installation) · 10.0.0 to before publication
Microsoft
Windows Server, version 1909 (Server Core installation) · 10.0.0 to before publication
Microsoft
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 3.1): Local · Low privileges required · No user interaction required
Attack conditions (NVD, CVSS 3.1): Local · Low privileges required · No user interaction required
What an attacker can do
An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Vendor/CNA’s CVSS 3.1 assessment (base score 7.0/10) rates confidentiality, integrity and availability impact as high. NVD’s CVSS 3.1 assessment (base score 7.8/10) rates confidentiality, integrity and availability impact as high.
- CWE
- CWE-787
- CCR priority
- 44.7 /100 (P3)
- CVSS 3.1
- 7.8 /10 · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H · NVD
- EPSS
- 0.54158 · percentile 0.98983 · 2026-10-06
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-07 19:02:04.772962+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2020-1054.html