Synced 30 Sept 2026 20:54 UTC Account
← All products

CVE-2020-1507

HIGH severity · CVSS 7.9
7.9CVSS HIGH

Summary

<p>An elevation of privilege vulnerability exists in the way that Microsoft COM for Windows handles objects in memory. An attacker who successfully exploited the vulnerability could gain elevated privileges on a targeted system.</p> <p>To exploit the vulnerability, a user would have to open a specially crafted file.</p> <p>The security update addresses the vulnerability by correcting how Microsoft COM for Windows handles objects in memory.</p>

Impact & exploitability

Attack vectorLocal
Attack complexityLow
Privileges requiredNone
User interactionNone
Confidentiality impactLow
Integrity impactHigh
Availability impactNone
Exploit probability (EPSS)3%

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N

Affected products we track (1)

Recommendation

Apply the vendor fix promptly. Open any affected product above for its exact safe version.

Official patch: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1507 ↗