CVE-2020-0689HighCVSS 8.2
Microsoft Secure Boot Security Feature Bypass Vulnerability
🔗 CVE IDs covered (1)
📋 Description
A security feature bypass vulnerability exists in secure boot. An attacker who successfully exploited the vulnerability can bypass secure boot and load untrusted software. To exploit the vulnerability, an attacker could run a specially crafted application. The security update addresses the vulnerability by blocking vulnerable third-party bootloaders. For further information see Security update for Secure Boot DBX: January 12, 2021.
🎯 Affected products16
- Windows 10 Version 1607 for x64-based Systems
- Windows 10 Version 1803 for x64-based Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 Version 1909 for x64-based Systems
- Windows 10 for x64-based Systems
- Windows 8.1 for x64-based systems
- Windows Server 2012
- Windows Server 2012 (Server Core installation)
- Windows Server 2012 R2
- Windows Server 2012 R2 (Server Core installation)
- Windows Server 2016
- Windows Server 2016 (Server Core installation)
- Windows Server 2019
- Windows Server 2019 (Server Core installation)
- Windows Server, version 1803 (Server Core Installation)
- Windows Server, version 1909 (Server Core installation)
✅ Remediation
KB4535680 (Security Update) KB5012170 (Security Update) — fixed build 10.0.17763.3284 KB5012170 (Security Update) — fixed build 1.002 KB5012170 (Security Update) — fixed build 10.0.14393.5285 KB5012170 (Security Update) — fixed build V1.003 KB5012170 (Security Update) — fixed build V1.002
🔗 References (5)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-0689
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4535680
- referencehttps://support.microsoft.com/help/4535680
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5012170
- referencehttps://support.microsoft.com/help/5012170