CVE-2020-0965:Microsoft Windows Codecs Library Remote Code Execution Vulnerability (CVE-2020-0965)

splash
Back

Description Preview

A remote code execution vulnerability exists in the Microsoft Windows Codecs Library due to improper handling of objects in memory. An attacker who successfully exploits this vulnerability could execute arbitrary code on the affected system with the permissions of the current user. If the current user has administrative privileges, the attacker could take control of the affected system, install programs, view, change, or delete data, or create new accounts with full user rights.

Overview

CVE-2020-0965 is a critical vulnerability in the Microsoft Windows Codecs Library that could allow remote code execution. The vulnerability stems from the way the library handles objects in memory, which could be exploited by an attacker to execute malicious code. To exploit this vulnerability, an attacker would typically need to convince a user to open a specially crafted file or content that is designed to exploit the vulnerability. This could be achieved through social engineering tactics such as sending malicious email attachments or hosting malicious content on websites. The vulnerability affects various versions of Windows operating systems that use the affected Codecs Library component.

Remediation

To address this vulnerability, Microsoft has released security updates. Users and administrators should apply the appropriate security updates as soon as possible:

  1. Install the latest security updates from Microsoft by using Windows Update or Microsoft Update.
  2. Ensure that automatic updates are enabled to receive future security patches automatically.
  3. If you cannot apply the updates immediately, consider implementing workarounds such as:
    • Restricting access to the affected Codecs Library
    • Implementing additional access controls to limit user privileges
    • Using application control policies to prevent unknown or untrusted processes from executing
  4. Monitor Microsoft security advisories for any additional information or updated guidance related to this vulnerability.

References

  1. Microsoft Security Advisory: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0965
  2. Microsoft Security Response Center: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-0965
  3. National Vulnerability Database: https://nvd.nist.gov/vuln/detail/CVE-2020-0965
  4. Microsoft Windows Codecs Library documentation: https://docs.microsoft.com/en-us/windows/win32/medfound/codec-objects

Industry ExposureMost to least
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.

  1. Manufacturing
    Manufacturing
  2. Health Care & Social Assistance
    Health Care & Social Assistance
  3. Public Administration
    Public Administration
  4. Educational Services
    Educational Services
  5. Finance and Insurance
    Finance and Insurance
  6. Transportation & Warehousing
    Transportation & Warehousing
  7. Retail Trade
    Retail Trade
  8. Utilities
    Utilities
  9. Other Services (except Public Administration)
    Other Services (except Public Administration)
  10. Professional, Scientific, & Technical Services
    Professional, Scientific, & Technical Services
  11. Information
    Information
  12. Arts, Entertainment & Recreation
    Arts, Entertainment & Recreation
  13. Management of Companies & Enterprises
    Management of Companies & Enterprises
  14. Accommodation & Food Services
    Accommodation & Food Services
  15. Construction
    Construction
  16. Agriculture, Forestry Fishing & Hunting
    Agriculture, Forestry Fishing & Hunting
  17. Mining
    Mining
  18. Real Estate Rental & Leasing
    Real Estate Rental & Leasing
  19. Wholesale Trade
    Wholesale Trade
  20. Administrative, Support, Waste Management & Remediation Services
    Administrative, Support, Waste Management & Remediation Services

Focus on What Matters

  1. See Everything.
  2. Identify True Risk.
  3. Proactively Mitigate Threats.

Let's talk!

background
Armis Vulnerability Intelligence Database