mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-08 03:26:30 +00:00
51 lines
4.8 KiB
Markdown
51 lines
4.8 KiB
Markdown
![]() |
### [CVE-2020-1115](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1115)
|
||
|

|
||
|

|
||
|

|
||
|

|
||
|

|
||
|

|
||
|

|
||
|

|
||
|

|
||
|

|
||
|

|
||
|

|
||
|

|
||
|

|
||
|

|
||
|
&color=blue)
|
||
|

|
||
|
&color=blue)
|
||
|

|
||
|
&color=blue)
|
||
|
&color=blue)
|
||
|

|
||
|

|
||
|
&color=blue)
|
||
|

|
||
|
&color=blue)
|
||
|

|
||
|

|
||
|
&color=blue)
|
||
|
&color=blue)
|
||
|

|
||
|

|
||
|

|
||
|

|
||
|

|
||
|

|
||
|
|
||
|
### Description
|
||
|
|
||
|
<p>An elevation of privilege vulnerability exists when the <a href="https://technet.microsoft.com/library/security/dn848375.aspx#CLFS">Windows Common Log File System (CLFS)</a> driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p><p>To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted application to take control over the affected system.</p><p>The security update addresses the vulnerability by correcting how CLFS handles objects in memory.</p>
|
||
|
|
||
|
### POC
|
||
|
|
||
|
#### Reference
|
||
|
No PoCs from references.
|
||
|
|
||
|
#### Github
|
||
|
- https://github.com/404notf0und/CVE-Flow
|
||
|
|