CVE-2020-1574

medium
Published 2020-08-17 ยท Modified 2026-05-29
CVSS v3
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
5.5

Description

A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code. Exploitation of the vulnerability requires that a program process a specially crafted image file. The update addresses the vulnerability by correcting how Microsoft Windows Codecs Library handles objects in memory.

Predictions

Exploit likelihood
55%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Microsoft Security Response Center ยท View original โ†— ยท proprietary-no-redistribution
Full prose not cached โ€” VIR stores only structured fields (affected/fixed versions, references) for this source. Click "View original" above for the vendor's full advisory.

Affected

VendorProductVersion
microsoftWindows 7 for 32-bit Systems Service Pack 1
microsoftWindows 7 for x64-based Systems Service Pack 1
microsoftWindows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
microsoftWindows Server 2008 R2 for x64-based Systems Service Pack 1
microsoftMicrosoft SharePoint Server 2010 Service Pack 2
microsoftWindows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
microsoftInternet Explorer 9 on Windows Server 2008 for 32-bit Systems Service Pack 2
microsoftInternet Explorer 9 on Windows Server 2008 for x64-based Systems Service Pack 2
microsoftWindows Server 2012
microsoftWindows Server 2012 (Server Core installation)
microsoftMicrosoft Outlook 2013 RT Service Pack 1
microsoftWindows 8.1 for 32-bit systems
microsoftWindows 8.1 for x64-based systems
microsoftWindows Server 2012 R2
microsoftWindows RT 8.1
microsoftInternet Explorer 11 on Windows 7 for 32-bit Systems Service Pack 1
microsoftInternet Explorer 11 on Windows 7 for x64-based Systems Service Pack 1
microsoftInternet Explorer 11 on Windows Server 2008 R2 for x64-based Systems Service Pack 1
microsoftInternet Explorer 11 on Windows Server 2012
microsoftInternet Explorer 11 on Windows 8.1 for 32-bit systems
microsoftInternet Explorer 11 on Windows 8.1 for x64-based systems
microsoftInternet Explorer 11 on Windows Server 2012 R2
microsoftInternet Explorer 11 on Windows RT 8.1
microsoftInternet Explorer 11 on Windows 10 for 32-bit Systems
microsoftInternet Explorer 11 on Windows 10 for x64-based Systems
microsoftInternet Explorer 11 on Windows Server 2016
microsoftInternet Explorer 11 on Windows 10 Version 1607 for 32-bit Systems
microsoftInternet Explorer 11 on Windows 10 Version 1607 for x64-based Systems
microsoftInternet Explorer 11 on Windows 10 Version 1709 for 32-bit Systems
microsoftInternet Explorer 11 on Windows 10 Version 1709 for x64-based Systems

OS impact

OSVersionStatusFixed in
windows windows1909affected
windows windows2004affected

References

CWEs

CWE-119

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.