CVE-2020-17087
Microsoft Windows Server 2016 1903 … 20h2
Raw vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HCVSS and EPSS are reproduced from their sources (NVD, FIRST EPSS). Risk Priority is our own derived reading, not an NVD score.
Summary
CVE-2020-17087 is a high-severity Incorrect Calculation of Buffer Size (CWE-131) vulnerability in Microsoft Windows Server 2016. Its CVSS base score is 7.8 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploitation for Privilege Escalation (T1068); ranked in the top 8% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
The vulnerability CVE-2020-17087 is a Windows Kernel Local Elevation of Privilege Vulnerability affecting the Windows kernel. It is associated with CWE-131 and has a CVSS 3.1 score of 7.8 reflecting local attack vector, low attack complexity, and low privileges required.
An attacker with local access and low privileges can exploit the flaw without user interaction to obtain full elevation of privileges, resulting in high impact to confidentiality, integrity, and availability on the affected system.
Microsoft has published security guidance for the issue via its advisory portal, and the vulnerability appears in the CISA catalog of known exploited vulnerabilities.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2020-9042
Vulnerability Data
Windows Kernel Local Elevation of Privilege Vulnerability
- CWE(s)
- KEV Date Added
- 03 November 2021
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly prevent buffer-size miscalculations via coding standards, reviews, and testing, while fixing this single weakness only partially fulfills the broader control.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Secure coding standards directly require correct buffer-size calculations.
Security testing can detect buffer-size errors before release.
Secure development lifecycle mandates size-checking practices that reduce buffer-size miscalculations.
Application security requirements can specify buffer-size validation rules.
Secure architecture principles include safe memory-allocation guidelines.