CVE detail
CVE-2020-1425
A remoted code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory, aka 'Microsoft Windows Codecs Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1457.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 17.9 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
5 source links · newest first
- July 2020 Patch Tuesday forecast: Will the CVE trend continue?Help Net Security
Microsoft has averaged roughly 90 common vulnerabilities and exposures (CVE) fixes per month over the past five months. With everyone working from home and apparently focused on bug fixes, I expect this large CVE fixing trend to continue. Despite these record CVE numbers, the actual number of updates have been down; we haven’t seen Exchange or SQL Server updates in a while. The hot topic of conversation over the last two weeks has been the … More →
newswww.helpnetsecurity.comJul 10, 2020, 5:30 AM - 6th July – Threat Intelligence BulletinCheck Point Research
For the latest discoveries in cyber research for the week of 6th July 2020, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Roblox, a multiplayer game platform, has suffered a data breach in which more than 1,800 user profiles were defaced with messages in support of Donald Trump’s reelection campaign, and their avatars’ […]
vendorresearch.checkpoint.comJul 6, 2020, 1:18 PM - Microsoft fixes two RCE flaws affecting Windows 10 machinesHelp Net Security
Microsoft has released fixes for two remote code execution (RCE) vulnerabilities in the Microsoft Windows Codecs Library on Windows 10 machines. The vulnerabilities Both flaws – CVE-2020-1425 and CVE-2020-1457 – arose because of the way the Microsoft Windows Codecs Library handled objects in memory. CVE-2020-1425 could allow attackers to obtain information to further compromise the user’s system, and CVE-2020-1457 would allow them to execute arbitrary code, all by tricking users into opening an image file. … More →
newswww.helpnetsecurity.comJul 2, 2020, 9:08 AM Microsoft has silently released an emergency security update through the Windows Store app to address two vulnerabilities in Windows codecs. Microsoft has silently released two out-of-band security updates through the Windows Store app to address two vulnerabilities in the Windows Codecs Library. The two issues are remote code execution vulnerabilities tracked as CVE-2020-1425 & CVE-2020-1457 that impact Windows 10 […]
newssecurityaffairs.comJul 1, 2020, 8:57 AMMicrosoft on Tuesday published advisories to provide details on two remote code execution vulnerabilities addressed in the Windows Codecs Library. Both of these vulnerabilities are related to the manner in which the affected Windows component handles objects in memory and both feature a CVSS score of 7.3.
newswww.securityweek.comJul 1, 2020, 8:20 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2023-36697CVSS 6.8 · Medium
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- CVE-2023-36606CVSS 7.5 · High
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
- CVE-2023-36593CVSS 7.8 · High
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- CVE-2023-36592CVSS 7.3 · High
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- CVE-2023-36591CVSS 7.3 · High
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- CVE-2023-36590CVSS 7.3 · High
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability