CVE-2020-17087
Microsoft Windows Server 2016 1903 … 20h2
Raw vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HSummary
CVE-2020-17087 is a high-severity Incorrect Calculation of Buffer Size (CWE-131) vulnerability in Microsoft Windows Server 2016. Its CVSS base score is 7.8 (High).
Operationally, ranked in the top 8% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.
The strongest mitigations our analysis identified map to AC-3 (Access Enforcement) and SI-2 (Flaw Remediation) — see the control section below for these in your framework.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
The vulnerability CVE-2020-17087 is a Windows Kernel Local Elevation of Privilege Vulnerability affecting the Windows kernel. It is associated with CWE-131 and has a CVSS 3.1 score of 7.8 reflecting local attack vector, low attack complexity, and low privileges required.
An attacker with local access and low privileges can exploit the flaw without user interaction to obtain full elevation of privileges, resulting in high impact to confidentiality, integrity, and availability on the affected system.
Microsoft has published security guidance for the issue via its advisory portal, and the vulnerability appears in the CISA catalog of known exploited vulnerabilities.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2020-9042
Vulnerability Data
Windows Kernel Local Elevation of Privilege Vulnerability
- CWE(s)
- KEV Date Added
- 03 November 2021
Related Threats
Likely ATT&CK TechniquesAI
Techniques this vulnerability likely enables, inferred from its description, weakness type, and attributed-actor tradecraft. Confidence is per-technique.
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
Mitigating Controls (NIST 800-53 r5) AI
Directly enforces kernel-level access decisions so a low-privileged local process cannot obtain unauthorized elevated rights.
Requires timely application of the vendor patch that eliminates the buffer-size flaw before exploitation can succeed.
Limits the set of privileges initially granted to any local account, reducing the value an attacker can obtain even if the kernel flaw is triggered.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly prevent buffer-size miscalculations via coding standards, reviews, and testing, while fixing this single weakness only partially fulfills the broader control.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Secure coding standards directly require correct buffer-size calculations.
Security testing can detect buffer-size errors before release.
Secure development lifecycle mandates size-checking practices that reduce buffer-size miscalculations.
Application security requirements can specify buffer-size validation rules.
Secure architecture principles include safe memory-allocation guidelines.