Vulnerability record · CVE-2020-1300 · published 9 June 2020
CVE-2020-1300: Windows Cabinet File Handling Remote Code Execution
Microsoft · Windows 10
Windows fails to properly handle cabinet (.cab) files, allowing remote code execution. An attacker must convince a user to open a crafted cabinet file or spoof a network printer to deliver a malicious cabinet disguised as a printer driver. The flaw affects a broad set of Windows client and server versions and carries a high CVSS score.
Description
A remote code execution vulnerability exists when Microsoft Windows fails to properly handle cabinet files.To exploit the vulnerability, an attacker would have to convince a user to either open a specially crafted cabinet file or spoof a network printer and trick a user into installing a malicious cabinet file disguised as a printer driver.The update addresses the vulnerability by correcting how Windows handles cabinet files., aka 'Windows Remote Code Execution Vulnerability'.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability and high EPSS, but exploitation requires user interaction and no KEV or confirmed public exploit is recorded.
What it is
Windows fails to properly handle cabinet (.cab) files, allowing remote code execution. An attacker must convince a user to open a crafted cabinet file or spoof a network printer to deliver a malicious cabinet disguised as a printer driver. The flaw affects a broad set of Windows client and server versions and carries a high CVSS score.
Impact
Successful exploitation gives the attacker code execution in the context of the victim user, with high confidentiality, integrity and availability impact. This can lead to full system compromise of the affected host.
Attack surface
Reached over the network (AV:N) with no privileges required (PR:N), but user interaction is required (UI:R) since the victim must open the file or install the spoofed printer driver. No authentication is needed to deliver the payload.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented; EPSS is high at roughly 0.59 (99th percentile), and the only references are Microsoft patch advisories, so no public exploit code is confirmed by this record.
What to do
- Apply the Microsoft security update for CVE-2020-1300 on all affected Windows versions as the first action.
- Restrict or block untrusted .cab file execution and delivery via email, web downloads and removable media.
- Harden printer driver installation, for example by limiting Point and Print and driver installation to trusted servers.
- Educate users not to open unexpected cabinet files or install printer drivers from untrusted network sources.
- Segment and monitor networks to reduce the reach of spoofed printer or file-share delivery paths.
Detection
- Monitor process creation for cab extraction or installer utilities (e.g. expand.exe, extrac32.exe, rundll32.exe) spawned from email clients, browsers or file shares.
- Alert on printer driver installation events and Point and Print activity from untrusted or unexpected servers.
- Hunt for .cab files written to user-writable directories or temp paths shortly before process execution.
- Review Windows event logs for suspicious driver installation and unexpected child processes from document or print handlers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
8 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1300 | PatchVendor Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1300 | PatchVendor Advisory |
Track CVE-2020-1300 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-1300), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.