A remote code execution vulnerability exists when Windows Media Audio Codec improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit a malicious webpage.
The security update addresses the vulnerability by correcting how Windows Media Audio Codec handles objects.
References
Link | Resource |
---|---|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1339 | Patch Vendor Advisory |
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1339 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 05:10
Type | Values Removed | Values Added |
---|---|---|
References | () https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1339 - Patch, Vendor Advisory |
19 Jan 2024, 00:15
Type | Values Removed | Values Added |
---|---|---|
Summary | A remote code execution vulnerability exists when Windows Media Audio Codec improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit a malicious webpage. The security update addresses the vulnerability by correcting how Windows Media Audio Codec handles objects. |
04 Jan 2024, 02:15
Type | Values Removed | Values Added |
---|---|---|
Summary | <p>A remote code execution vulnerability exists when Windows Media Audio Codec improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system.</p> <p>There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit a malicious webpage.</p> <p>The security update addresses the vulnerability by correcting how Windows Media Audio Codec handles objects.</p> | |
CVSS |
v2 : v3 : |
v2 : 9.3
v3 : 7.8 |
Information
Published : 2020-08-17 19:15
Updated : 2024-11-21 05:10
NVD link : CVE-2020-1339
Mitre link : CVE-2020-1339
CVE.ORG link : CVE-2020-1339
JSON object : View
Products Affected
microsoft
- windows_8.1
- windows_10
- windows_7
- windows_server_2019
- windows_rt_8.1
- windows_server_2012
- windows_server_2008
- windows_server_2016
CWE