7.2 High
CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:L/Au:N/C:C/I:C/A:C
8.1 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
7.4 High
AI Score
Confidence
High
0.009 Low
EPSS
Percentile
82.8%
Multiple vulnerabilities were found in Microsoft Products (Extended Support Update). Malicious users can exploit these vulnerabilities to gain privileges, obtain sensitive information.
Below is a complete list of vulnerabilities:
Malware exists for this vulnerability. Usually such malware is classified as Exploit. More details.
CVE-2020-16964 critical
CVE-2020-16960 critical
CVE-2020-17140 critical
CVE-2020-16962 critical
CVE-2020-16963 critical
CVE-2020-16961 critical
CVE-2020-17098 high
CVE-2020-16959 critical
CVE-2020-16958 critical
Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)
Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.
Privilege escalation. Exploitation of vulnerabilities with this impact can lead to performing by abuser actions, which are normally disallowed for current role.
support.microsoft.com/kb/4592471
support.microsoft.com/kb/4592498
support.microsoft.com/kb/4592503
support.microsoft.com/kb/4592504
nvd.nist.gov/vuln/detail/CVE-2020-16958
nvd.nist.gov/vuln/detail/CVE-2020-16959
nvd.nist.gov/vuln/detail/CVE-2020-16960
nvd.nist.gov/vuln/detail/CVE-2020-16961
nvd.nist.gov/vuln/detail/CVE-2020-16962
nvd.nist.gov/vuln/detail/CVE-2020-16963
nvd.nist.gov/vuln/detail/CVE-2020-16964
nvd.nist.gov/vuln/detail/CVE-2020-17098
nvd.nist.gov/vuln/detail/CVE-2020-17140
portal.msrc.microsoft.com/api/security-guidance/en-US/CVE/ADV200013
statistics.securelist.com/
threats.kaspersky.com/en/class/Exploit/
threats.kaspersky.com/en/product/Microsoft-Windows-10/
threats.kaspersky.com/en/product/Microsoft-Windows-7/
threats.kaspersky.com/en/product/Microsoft-Windows-8/
threats.kaspersky.com/en/product/Microsoft-Windows-Server-2008/
threats.kaspersky.com/en/product/Microsoft-Windows-Server-2012/
threats.kaspersky.com/en/product/Microsoft-Windows-Server/
threats.kaspersky.com/en/product/Microsoft-Windows/
threats.kaspersky.com/en/product/Windows-RT/
7.2 High
CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:L/Au:N/C:C/I:C/A:C
8.1 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
7.4 High
AI Score
Confidence
High
0.009 Low
EPSS
Percentile
82.8%