EXPOSURES › CVE-2020-1027
CVE-2020-1027
HIGH ⌖ ON CISA KEV · EXPLOITEDA Windows kernel privilege escalation flaw allowed attackers to gain elevated permissions and execute arbitrary code.
This kernel-level vulnerability enabled attackers to escalate privileges and execute code with elevated permissions, directly violating CMMC/NIST 800-171 requirements for system integrity and access control. DIB organizations must ensure all Windows systems are patched immediately, as this flaw was actively exploited in the wild and represents a severe, avoidable exposure.
Shame score — A fundamental kernel vulnerability that was actively exploited in the wild, demonstrating severe negligence in patch management and system hardening.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |