← All CVEs

CVE-2020-1286

high · 8.8

A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths.An attacker who successfully exploited this vulnerability could run arbitrary code in the context of the current user, aka 'Windows Shell Remote Code Execution Vulnerability'.

8.8
CVSS
11.8%
EPSS (exploit prob.)
96th
EPSS percentile
2020-06-09
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
microsoftwindows_101803
microsoftwindows_101809
microsoftwindows_101903
microsoftwindows_101909
microsoftwindows_102004
microsoftwindows_server_20161803
microsoftwindows_server_20161903
microsoftwindows_server_20161909
microsoftwindows_server_20162004
microsoftwindows_server_2019all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-1286