CVE-2020-1425 (CNNVD-202006-1888)
中文标题:
Microsoft Windows Codecs Library 缓冲区错误漏洞
英文标题:
A remoted code execution vulnerability exists in the way that Microsoft Windows Codecs Library handl...
漏洞描述
中文描述:
Microsoft Windows Codecs Library是美国微软(Microsoft)公司的微软Windows系统得一个功能库。 Microsoft Windows Codecs Library中处理内存对象的方法存在缓冲区错误漏洞。攻击者可借助特制的文件利用该漏洞获取信息,进一步入侵用户系统。以下产品及受到影响:Microsoft Windows 10 1709版本,Windows 10 1803版本,Windows 10 1809版本,Windows 10 1903版本,Windows 10 1909版本,Windows 10 2004版本,Windows Server 2019,Windows Server 1803版本,Windows Server 1903版本,Windows Server 2004版本,Windows Server 1909版本。
英文描述:
A remoted code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka 'Microsoft Windows Codecs Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1457.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Microsoft | Windows 10 Version 2004 for x64-based Systems | unspecified | - | - |
cpe:2.3:a:microsoft:windows_10_version_2004_for_x64-based_systems:unspecified:*:*:*:*:*:*:*
|
| Microsoft | Windows 10 Version 2004 for 32-bit Systems | unspecified | - | - |
cpe:2.3:a:microsoft:windows_10_version_2004_for_32-bit_systems:unspecified:*:*:*:*:*:*:*
|
| Microsoft | Windows 10 Version 2004 for ARM64-based Systems | unspecified | - | - |
cpe:2.3:a:microsoft:windows_10_version_2004_for_arm64-based_systems:unspecified:*:*:*:*:*:*:*
|
| Microsoft | Windows 10 Version 1803 for 32-bit Systems | unspecified | - | - |
cpe:2.3:a:microsoft:windows_10_version_1803_for_32-bit_systems:unspecified:*:*:*:*:*:*:*
|
| Microsoft | Windows 10 Version 1803 for x64-based Systems | unspecified | - | - |
cpe:2.3:a:microsoft:windows_10_version_1803_for_x64-based_systems:unspecified:*:*:*:*:*:*:*
|
| Microsoft | Windows 10 Version 1803 for ARM64-based Systems | unspecified | - | - |
cpe:2.3:a:microsoft:windows_10_version_1803_for_arm64-based_systems:unspecified:*:*:*:*:*:*:*
|
| Microsoft | Windows 10 Version 1809 for 32-bit Systems | unspecified | - | - |
cpe:2.3:a:microsoft:windows_10_version_1809_for_32-bit_systems:unspecified:*:*:*:*:*:*:*
|
| Microsoft | Windows 10 Version 1809 for x64-based Systems | unspecified | - | - |
cpe:2.3:a:microsoft:windows_10_version_1809_for_x64-based_systems:unspecified:*:*:*:*:*:*:*
|
| Microsoft | Windows 10 Version 1809 for ARM64-based Systems | unspecified | - | - |
cpe:2.3:a:microsoft:windows_10_version_1809_for_arm64-based_systems:unspecified:*:*:*:*:*:*:*
|
| Microsoft | Windows 10 Version 1909 for 32-bit Systems | unspecified | - | - |
cpe:2.3:a:microsoft:windows_10_version_1909_for_32-bit_systems:unspecified:*:*:*:*:*:*:*
|
| Microsoft | Windows 10 Version 1909 for x64-based Systems | unspecified | - | - |
cpe:2.3:a:microsoft:windows_10_version_1909_for_x64-based_systems:unspecified:*:*:*:*:*:*:*
|
| Microsoft | Windows 10 Version 1909 for ARM64-based Systems | unspecified | - | - |
cpe:2.3:a:microsoft:windows_10_version_1909_for_arm64-based_systems:unspecified:*:*:*:*:*:*:*
|
| Microsoft | Windows 10 Version 1709 for 32-bit Systems | unspecified | - | - |
cpe:2.3:a:microsoft:windows_10_version_1709_for_32-bit_systems:unspecified:*:*:*:*:*:*:*
|
| Microsoft | Windows 10 Version 1709 for x64-based Systems | unspecified | - | - |
cpe:2.3:a:microsoft:windows_10_version_1709_for_x64-based_systems:unspecified:*:*:*:*:*:*:*
|
| Microsoft | Windows 10 Version 1709 for ARM64-based Systems | unspecified | - | - |
cpe:2.3:a:microsoft:windows_10_version_1709_for_arm64-based_systems:unspecified:*:*:*:*:*:*:*
|
| Microsoft | Windows 10 Version 1903 for 32-bit Systems | unspecified | - | - |
cpe:2.3:a:microsoft:windows_10_version_1903_for_32-bit_systems:unspecified:*:*:*:*:*:*:*
|
| Microsoft | Windows 10 Version 1903 for x64-based Systems | unspecified | - | - |
cpe:2.3:a:microsoft:windows_10_version_1903_for_x64-based_systems:unspecified:*:*:*:*:*:*:*
|
| Microsoft | Windows 10 Version 1903 for ARM64-based Systems | unspecified | - | - |
cpe:2.3:a:microsoft:windows_10_version_1903_for_arm64-based_systems:unspecified:*:*:*:*:*:*:*
|
| microsoft | windows_10 | 1709 | - | - |
cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:*
|
| microsoft | windows_10 | 1803 | - | - |
cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:*
|
| microsoft | windows_10 | 1809 | - | - |
cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:*
|
| microsoft | windows_10 | 1903 | - | - |
cpe:2.3:o:microsoft:windows_10:1903:*:*:*:*:*:*:*
|
| microsoft | windows_10 | 1909 | - | - |
cpe:2.3:o:microsoft:windows_10:1909:*:*:*:*:*:*:*
|
| microsoft | windows_10 | 2004 | - | - |
cpe:2.3:o:microsoft:windows_10:2004:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2020-1425 |
2025-11-11 15:20:27 | 2025-11-11 07:36:03 |
| NVD | nvd_CVE-2020-1425 |
2025-11-11 14:57:01 | 2025-11-11 07:44:30 |
| CNNVD | cnnvd_CNNVD-202006-1888 |
2025-11-11 15:10:27 | 2025-11-11 07:56:15 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 缓冲区错误
- cnnvd_id: 未提取 -> CNNVD-202006-1888
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.HIGH
- cvss_score: 未提取 -> 7.8
- cvss_vector: NOT_EXTRACTED -> CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- cvss_version: NOT_EXTRACTED -> 3.1
- affected_products_count: 18 -> 24
- data_sources: ['cve'] -> ['cve', 'nvd']