CVE-2020-1027

HIGH(7.8)KEV

Microsoft Windows Kernel Privilege Escalation Vulnerability

Description

CVE-2020-1027 is an elevation of privilege vulnerability in the Windows Kernel caused by improper handling of objects in memory. This vulnerability affects Microsoft Windows systems and allows a local attacker who has already gained initial access to execute code with elevated permissions, potentially achieving full SYSTEM-level control. The vulnerability was added to CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. With an EPSS percentile of 92.7%, CVE-2020-1027 represents a significant threat that organizations running affected Windows versions should remediate immediately.

KEV Information

Vendor
Microsoft
Product
Windows
Date Added
May 23, 2022
Due Date
June 13, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
microsoftwindows 10 1507-
microsoftwindows 10 1607-
microsoftwindows 10 1709-
microsoftwindows 10 1803-
microsoftwindows 10 1809-
microsoftwindows 10 1903-
microsoftwindows 10 1909-
microsoftwindows 7-
microsoftwindows 8.1-
microsoftwindows rt 8.1-
microsoftwindows server 1803-
microsoftwindows server 1903-
microsoftwindows server 1909-
microsoftwindows server 2008-; r2
microsoftwindows server 2012-; r2
microsoftwindows server 2016-
microsoftwindows server 2019-

Multiple CVSS Assessments

Source: [email protected](Primary)
7.8
HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
7.8
HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-269: Improper Privilege Management

CWE-269 describes weaknesses where a product does not properly assign, modify, track, or check the privileges of an actor, causing the actor to gain more access than intended. In CVE-2020-1027, the Windows Kernel fails to correctly manage privilege boundaries during memory object operations, enabling an attacker to escalate from a lower integrity level to full system-level execution privileges.

Learn more: CWE-269 — Improper Privilege Management

Impact Analysis

CVE-2020-1027 is a locally exploitable elevation of privilege vulnerability in the Windows Kernel that allows an attacker with initial low-privilege access to execute arbitrary code with SYSTEM-level permissions. The attack requires local access to the target system, meaning an attacker must already have a foothold — typically obtained through phishing, a separate remote vulnerability, or malware delivery. Once exploited, the attacker gains full control over the affected system, compromising confidentiality, integrity, and availability of all data and services running on the machine. The EPSS percentile of 92.7% indicates a high probability of exploitation activity, and the inclusion in CISA's KEV catalog confirms that threat actors have leveraged this vulnerability in real-world attacks. Organizations should treat this as a high-priority patching target, especially given the kernel-level access that successful exploitation provides.

Exploit Maturity

CISA has confirmed active exploitation of CVE-2020-1027 in the wild by including it in the Known Exploited Vulnerabilities catalog with a remediation deadline of June 13, 2022. The EPSS percentile of 92.7% indicates a very high probability of exploitation, placing this vulnerability well above typical kernel privilege escalation flaws in terms of real-world exploitation activity. As a Windows Kernel vulnerability, it is commonly used as a post-exploitation tool to gain SYSTEM privileges after initial access has been obtained through other means, making it a valuable component in multi-stage attack chains.

Remediation

  1. Apply the security updates provided by Microsoft for the affected Windows versions as specified in the associated security advisory. CISA requires federal agencies to remediate by June 13, 2022.
  2. Prioritize patching on systems that are externally exposed or used by privileged users, as this vulnerability is most dangerous when chained with initial access exploits.
  3. Implement endpoint detection and response (EDR) solutions configured to detect suspicious kernel-mode activity and privilege escalation attempts, including unusual process token manipulation.
  4. Review system logs and security event logs for indicators of privilege escalation, particularly events showing unexpected transitions from low-integrity to SYSTEM-level processes.
  5. Apply the principle of least privilege across all user accounts and services to limit the potential impact if an attacker gains initial foothold access before exploiting this kernel vulnerability.

Technical Details

CVE-2020-1027 stems from a flaw in how the Windows Kernel manages objects in memory, which aligns with improper privilege management weaknesses. When the kernel processes certain memory objects, it fails to properly validate or enforce privilege boundaries, allowing a local attacker to manipulate these objects in a way that elevates their execution context from a low-integrity or user-mode process to SYSTEM-level privileges. The attack is local in nature, meaning an adversary must first achieve code execution on the target system through another vector such as a phishing payload or a remote code execution vulnerability. Once local access is obtained, the attacker triggers the kernel vulnerability to gain full control over the operating system. This type of kernel elevation of privilege is particularly dangerous because it operates below the security boundaries enforced by user-mode protections, making detection difficult without specialized kernel-level monitoring.

Frequently Asked Questions

Is CVE-2020-1027 being actively exploited?

Yes, CVE-2020-1027 is being actively exploited. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog, confirming real-world exploitation. The EPSS percentile of 92.7% further indicates a high likelihood of exploitation activity.

What products are affected by CVE-2020-1027?

CVE-2020-1027 affects Microsoft Windows operating systems. The vulnerability resides in the Windows Kernel component, and multiple Windows versions are impacted. Administrators should consult Microsoft's security advisory for the specific list of affected OS versions.

How do I fix CVE-2020-1027?

Apply the security updates provided by Microsoft as soon as possible. Prioritize patching on systems with higher exposure risk. Additionally, implement endpoint monitoring to detect privilege escalation attempts while patches are being rolled out.

How severe is CVE-2020-1027?

CVE-2020-1027 is a serious elevation of privilege vulnerability in the Windows Kernel. Its EPSS percentile of 92.7% places it among the most likely-to-be-exploited vulnerabilities. Successful exploitation grants SYSTEM-level access, making it a critical threat that should be remediated promptly.

CVSS Score

7.8
HIGH(7.8)

EPSS Score

EPSS Score4.55%
EPSS Percentile90.8%

Dates

PublishedApril 15, 2020
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.