LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-17087: Microsoft Windows Kernel Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-17087 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation.

CVE-2020-17087 is a privilege-escalation vulnerability in the Microsoft Windows kernel. An attacker who already has some level of access on a system could abuse it to gain higher privileges. Because the flaw sits in the kernel, successful exploitation can undermine isolation between user processes and the operating system itself, which is why it matters for any organization running Windows endpoints or servers.

Public detail on exact mechanics is limited; defenders should treat it as a kernel elevation-of-privilege issue and confirm all version and patch specifics directly against the Microsoft advisory.

How it works

The vulnerability is classified under CWE-131 (Incorrect Calculation of Buffer Size). In this class of weakness, code that manages memory fails to compute the correct size for a buffer. When that miscalculation occurs inside kernel components, an attacker who can supply crafted input may cause the kernel to write or read outside the intended bounds.

For a privilege-escalation scenario, the typical abuse path is: the attacker first obtains code execution in a lower-privileged context (for example, a standard user process or a compromised application), then triggers the flawed kernel path so that the resulting memory corruption elevates the attacker’s token or allows arbitrary kernel-mode execution. Exact trigger conditions and exploit primitives are not detailed in the provided summary; treat any public proof-of-concept claims cautiously and validate them only against vendor or trusted researcher write-ups.

Am I affected? How to find it in your systems

The affected product is Microsoft Windows. The vulnerability resides in the kernel, so it can appear on workstations, laptops, servers, and virtual machines running supported or previously supported Windows releases. Confirm the precise builds that are vulnerable by consulting the Microsoft security advisory for CVE-2020-17087; do not rely on version lists from secondary sources.

How to remediate

Patch first. Apply the security updates Microsoft released for this CVE exactly as described in the vendor advisory. CISA’s required action is to apply updates per vendor instructions; follow that guidance and verify installation through your patch-management console or by checking the OS build/update history on each host.

If you can't patch immediately

When immediate patching is blocked by change windows or compatibility testing, apply compensating controls while you schedule the update.

Compensating controls are temporary. Track the exception and apply the vendor update as soon as practicable.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities are commonly used after an initial compromise to deepen access, disable security tools, or stage further theft. The facts available for CVE-2020-17087 do not document ransomware use, yet any successful elevation still warrants investigation of the affected hosts for persistence, credential access, and data staging. Review endpoint and identity logs for the period of exposure, rotate credentials that may have been accessible from the compromised context, and follow your incident-response plan. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether associated accounts appear in prior leaks.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-131
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities