Skip to content
COOEY

EXPOSURES › CVE-2020-1054

CVE-2020-1054

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-1054 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 exploited-in-wildunpatchedrceprivilege-escalation

A kernel-mode privilege escalation flaw in Microsoft Win32k allowed attackers to execute arbitrary code in kernel mode.

This vulnerability in the Windows kernel-mode driver failed to properly handle memory objects, enabling kernel-mode code execution. DIB organizations must ensure all Windows systems are patched immediately, as this flaw was actively exploited in the wild and represents a severe, avoidable security failure.

Shame score — A fundamental kernel-mode privilege escalation flaw that was actively exploited in the wild, demonstrating severe negligence in patching and system hardening.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Microsoft's kernel-mode privilege escalation flaw represents a critical systemic failure in Windows security, allowing arbitrary code execution at the highest privilege level. The severity of the vuln
cooey ↗ severe-fallout -0.80
The NVD entry confirms the critical nature of the vulnerability, allowing kernel-mode code execution, which is a severe systemic failure in Windows security.
"Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode."
app.opencve.io ↗ severe-fallout -0.50
OpenCVE lists Microsoft vulnerabilities but provides no specific commentary on CVE-2020-1054, merely aggregating CVE data.
NVD ↗ severe-fallout -0.50
NVD page for a different CVE (2026-10547) shows no relevant commentary on CVE-2020-1054.
www.cvefind.com ↗ severe-fallout -0.50
CVE Find provides no specific commentary on CVE-2020-1054.
CISA ↗ severe-fallout -0.50
CISA adds exploited vulnerabilities to its catalog but provides no specific commentary on CVE-2020-1054.
cvedb.shodan.io ↗ severe-fallout -0.50
CVEDB API provides no specific commentary on CVE-2020-1054.
github.com ↗ severe-fallout -0.50
GitHub repository for CISA KEV data provides no specific commentary on CVE-2020-1054.
AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized