
CVE-2020-0875 – Microsoft splwow64 Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2020-0875
11 Sep 2020 —
An information disclosure vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system (low-integrity to medium-integrity).
This vulnerability by itself does not allow arbitrary code execution; however, it could allow arbitrary code to be run if the attacker uses it in combination with another vulnerability (such as a remote code execution vulnerability or another elevation... • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0875 •

CVE-2020-0878 – Microsoft Edge and Internet Explorer Memory Corruption Vulnerability
https://notcve.org/view.php?id=CVE-2020-0878
11 Sep 2020 —
A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, the attacker could take control of an affected system. An attacker could then install pr... • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0878 • CWE-787: Out-of-bounds Write •

CVE-2020-0856 – Active Directory Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2020-0856
11 Sep 2020 —
An information disclosure vulnerability exists when Active Directory integrated DNS (ADIDNS) mishandles objects in memory. An authenticated attacker who successfully exploited this vulnerability would be able to read sensitive information about the target system.
To exploit this condition, an authenticated attacker would need to send a specially crafted request to the AD|DNS service. Note that the information disclosure vulnerability by itself would not be sufficient for an attacker to compromise ... • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0856 •

CVE-2020-0870 – Shell infrastructure component Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2020-0870
11 Sep 2020 —
An elevation of privilege vulnerability exists when the Shell infrastructure component improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.
The update addresses the vulnerability by corre... • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0870 •

CVE-2020-0839 – Windows dnsrslvr.dll Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2020-0839
11 Sep 2020 —
An elevation of privilege vulnerability exists in the way that the dnsrslvr.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.
To exploit the vulnerability, a locally authenticated attacker could run a specially crafted application.
The security update addresses the vulnerability by ensuring the dnsrslvr.dll properly handles objects in memory.
Se presenta una vulnerabilidad de escalada de privilegios en l... • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0839 •
CVE-2020-0838 – NTFS Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2020-0838
11 Sep 2020 —
An elevation of privilege vulnerability exists when NTFS improperly checks access. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
To exploit the vulnerability, an attacker would first have to log on to the system, and then run a specially crafted application to take control over the affected system.
The security update addresses the vulnerability by correcting how NTFS checks access.
Se presenta una vulnerabilidad de escalada de pri... • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0838 •
CVE-2020-0837 – ADFS MFA Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2020-0837
11 Sep 2020 —
An elevation of privilege vulnerability exists when Active Directory Federation Services (ADFS) improperly handles multi-factor authentication requests. An attacker who successfully exploited this vulnerability could bypass some, but not all, of the authentication factors.
To exploit this vulnerability, an attacker could send a specially crafted authentication request.
This security update corrects how ADFS handles multi-factor authentication requests.
Se presenta una vulnerabilidad de ... • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0837 •
CVE-2020-0836 – Windows DNS Denial of Service Vulnerability
https://notcve.org/view.php?id=CVE-2020-0836
11 Sep 2020 —
A denial of service vulnerability exists in Windows DNS when it fails to properly handle queries. An attacker who successfully exploited this vulnerability could cause the DNS service to become nonresponsive.
To exploit the vulnerability, an authenticated attacker could send malicious DNS queries to a target, resulting in a denial of service.
The update addresses the vulnerability by correcting how Windows DNS processes queries.
Se presenta una vulnerabilidad de denegación de servicio e... • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0836 •
CVE-2020-0790 – Microsoft splwow64 Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2020-0790
11 Sep 2020 —
A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system from low-integrity to medium-integrity.
This vulnerability by itself does not allow arbitrary code execution; however, it could allow arbitrary code to be run if the attacker uses it in combination with another vulnerability (such as a remote code execution vulnerability or another elevation of privile... • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0790 •

CVE-2020-0782 – Windows Cryptographic Catalog Services Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2020-0782
11 Sep 2020 —
An elevation of privilege vulnerability exists when the Windows Cryptographic Catalog Services improperly handle objects in memory. An attacker who successfully exploited this vulnerability could modify the cryptographic catalog.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.
The security update addresses the vulnerabil... • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0782 •