CVE detail
CVE-2020-17087
Windows Kernel Local Elevation of Privilege Vulnerability
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 27.7 · diversity 13.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
15 source links · newest first
- A threat actor exploited 11 zero-day flaws in 2020 campaignsSecurity Affairs
A hacking group has employed at least 11 zero-day flaws as part of an operation that took place in 2020 and targeted Android, iOS, and Windows users. Google’s Project Zero security team published a report about the activity of a mysterious hacking group that operated over the course of 2020 and exploited at least 11 […]
newssecurityaffairs.comMar 20, 2021, 8:11 PM - 16th November – Threat Intelligence BulletinCheck Point Research
For the latest discoveries in cyber research for the week of 16th November, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research has further investigated the newly revealed ‘Pay2Key’ ransomware, tracing several ransom payments to an Iranian cryptocurrency exchange, and concluded that the malware, which focuses on Israeli organizations, is most […]
vendorresearch.checkpoint.comNov 16, 2020, 5:19 PM - Security Affairs newsletter Round 289Security Affairs
A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box. Creative Office 365 phishing inverts images to avoid detection bots Luxottica data breach exposes info of LensCrafters and EyeMed patients Pwn2Own Tokyo Day 3: Team Flashback crowned Master of Pwn […]
newssecurityaffairs.comNov 15, 2020, 1:06 PM Here’s an overview of some of last week’s most interesting news and articles: Every employee has a cybersecurity blind spot 80% of companies say that an increased cybersecurity risk caused by human factors has posed a challenge during the COVID-19 pandemic, particularly in times of heightened stress. Microsoft advises users to stop using SMS- and voice-based MFA Multi-factor authentication (MFA) that depends on one of the authentication factors being delivered via SMS and voice calls … More →
newswww.helpnetsecurity.comNov 15, 2020, 9:30 AMMicrosoft Patch Tuesday updates for November 2020 address 112 flaws, including a Windows bug that was chained with Chrome issues in attacks. Microsoft Patch Tuesday updates for November 2020 address 112 vulnerabilities in multiple products, including Microsoft Windows, Office and Office Services and Web Apps, Internet Explorer (IE), Edge (EdgeHTML-based and Chromium-based), ChakraCore, Exchange Server, […]
newssecurityaffairs.comNov 11, 2020, 8:26 AM- November 2020 Patch Tuesday: Microsoft fixes actively exploited Windows Kernel flawHelp Net Security
On this November 2020 Patch Tuesday: Microsoft has plugged 112 security holes, including an actively exploited one Adobe has delivered security updates for Adobe Reader Mobile and Adobe Connect Intel has dropped a huge stack of security advisories and patches SAP has released 12 security notes and updated three previously released ones Mozilla has fixed a critical vulnerability affecting Firefox, Firefox ESR, and Thunderbird Microsoft’s updates Microsoft plugged 112 CVE-numbered flaws in a variety of … More →
newswww.helpnetsecurity.comNov 10, 2020, 8:43 PM Microsoft’s Patch Tuesday updates for November 2020 address more than 110 vulnerabilities, including a Windows flaw that was recently disclosed by Google after it was observed being exploited in attacks.
newswww.securityweek.comNov 10, 2020, 7:17 PM- Week in review: Windows zero-day exploited, Patch Tuesday forecast, selecting a compliance solutionHelp Net Security
Here’s an overview of some of last week’s most interesting news, reviews and articles: Git LFS vulnerability allows attackers to compromise targets’ Windows systems (CVE-2020-27955) A critical vulnerability (CVE-2020-27955) in Git Large File Storage (Git LFS), an open source Git extension for versioning large files, allows attackers to achieve remote code execution if the Windows-using victim is tricked into cloning the attacker’s malicious repository using a vulnerable Git version control tool, security researcher Dawid Golunski … More →
newswww.helpnetsecurity.comNov 8, 2020, 9:45 AM - Apple addresses three actively exploited iOS zero-daysSecurity Affairs
Apple released iOS 14.2 that addressed three zero-day vulnerabilities in its mobile OS that have been abused in attacks in the wild. Apple has addressed three iOS zero-day vulnerabilities actively exploited in attacks the wild and affecting iPhone, iPad, and iPod devices. The zero-day vulnerabilities have been fixed by the IT giant with the release of iOS […]
newssecurityaffairs.comNov 5, 2020, 9:33 PM - Google fixes two actively exploited Chrome zero-days (CVE-2020-16009, CVE-2020-16010)Help Net Security
For the third time in two weeks, Google has patched Chrome zero-day vulnerabilities that are being actively exploited in the wild: CVE-2020-16009 is present in the desktop version of the browser, CVE-2020-16010 in the mobile (Android) version. About the vulnerabilities (CVE-2020-16009, CVE-2020-16010) As per usual, Google has refrained from sharing much detail about each of the patched vulnerabilities, so all we know is this: CVE-2020-16009 is an inappropriate implementation flaw in V8, Chrome’s open source … More →
newswww.helpnetsecurity.comNov 4, 2020, 12:03 PM Google released Chrome 86.0.4240.183 for Windows, Mac, and Linux to fix 10 security vulnerabilities, including an RCE zero-day exploited in the wild. Google has released Chrome 86.0.4240.183 for Windows, Mac, and Linux that address ten security vulnerabilities including a remote code execution (RCE) zero-day (CVE-2020-16009) exploited by threat actors in the wild. The RCE is […]
newssecurityaffairs.comNov 3, 2020, 8:20 AM- 2nd November – Threat Intelligence BulletinCheck Point Research
For the latest discoveries in cyber research for the week of 2nd November, please download our Threat Intelligence Bulletin. Top Attacks and Breaches CISA, FBI and HHS have released a warning against an increase in Ryuk ransomware attacks on US hospitals. Check Point Research have shown that indeed, healthcare is currently the most targeted industry in […]
vendorresearch.checkpoint.comNov 2, 2020, 12:05 PM Google researchers have made public a Windows kernel zero day vulnerability (CVE-2020-17087) that is being exploited in the wild in tandem with a Google Chrome flaw (CVE-2020-15999) that has been patched on October 20. About CVE-2020-17087 CVE-2020-17087 is a vulnerability in the Windows Kernel Cryptography Driver, and “constitutes a locally accessible attack surface that can be exploited for privilege escalation (such as sandbox escape).” More technical information has been provided in the Chromium issue tracker … More →
newswww.helpnetsecurity.comNov 2, 2020, 10:48 AMGoogle researchers disclosed today a zero-day vulnerability in the Windows operating system that is currently under active exploitation. Security researchers from Google have disclosed a zero-day vulnerability in the Windows operating system, tracked as CVE-2020-17087, that is currently under active exploitation. Ben Hawkes, team lead for Google Project Zero team, revealed on Twitter that the vulnerability […]
newssecurityaffairs.comOct 30, 2020, 9:32 PMGoogle Project Zero security researchers have identified another Windows vulnerability that has been actively exploited in attacks.
newswww.securityweek.comOct 30, 2020, 6:24 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2021-26411CVSS 8.8 · High
Internet Explorer Memory Corruption Vulnerability
- CVE-2021-1647CVSS 7.8 · High
Microsoft Defender Remote Code Execution Vulnerability
KEV listed5 mentions - CVE-2020-0878CVSS 4.2 · Medium
<p>A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an at…
- CVE-2020-1464CVSS 7.8 · High
A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and lo…
- CVE-2020-1380CVSS 7.8 · High
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a…
- CVE-2021-43226CVSS 7.8 · High
Windows Common Log File System Driver Elevation of Privilege Vulnerability
KEV listed3 mentions