Vulnerability record · CVE-2020-17087 · published 11 November 2020
CVE-2020-17087: Windows Kernel Pool Buffer Overflow Local Privilege Escalation
Microsoft · Windows 10 1507
CVE-2020-17087 is a local elevation of privilege flaw in the Windows kernel, classified as CWE-131 (incorrect calculation of buffer size). A local attacker with low privileges can exploit the flaw to gain full control of the affected system, making it a serious post-compromise escalation vector.
Description
Windows Kernel Local Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is confirmed exploited in the wild per CISA KEV and allows full SYSTEM compromise from a local low-privileged position, though it requires an existing foothold.
What it is
CVE-2020-17087 is a local elevation of privilege flaw in the Windows kernel, classified as CWE-131 (incorrect calculation of buffer size). A local attacker with low privileges can exploit the flaw to gain full control of the affected system, making it a serious post-compromise escalation vector.
Impact
An attacker who already has a foothold on the machine can escalate from a low-privileged user to SYSTEM, gaining full control over the host. This enables credential theft, disabling of security controls, and lateral movement.
Attack surface
The vulnerability is reached locally (AV:L) with low privileges required (PR:L) and no user interaction (UI:N). No remote or network vector is present in the CVSS vector.
Exploitation
CVE-2020-17087 is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), confirming exploitation in the wild. EPSS gives a 30-day probability of 0.05431 (92.3rd percentile), indicating elevated likelihood relative to other CVEs.
What to do
- Apply the Microsoft security update referenced in the vendor advisory for all affected Windows versions.
- Prioritize patching of internet-facing and high-value endpoints, and verify patch status across Windows 7, 8.1, 10, and Windows Server 2008 through 2019.
- Enforce least privilege so that local users cannot easily run arbitrary code, reducing the value of the escalation path.
- Monitor for and restrict untrusted local code execution and suspicious driver or kernel-level activity.
- Track CISA KEV remediation due date (2022-05-03) and confirm closure.
Detection
- Monitor for unexpected processes gaining SYSTEM integrity level from low-privileged parent processes.
- Alert on unusual kernel pool allocations or crashes that may indicate exploitation attempts.
- Correlate local privilege escalation events with prior suspicious execution on the same host.
- Use EDR telemetry to detect known exploit patterns targeting the Windows kernel.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-17087 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Windows Kernel Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
15 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-17087 | PatchVendor Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-17087 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-17087 | US Government Resource |
Track CVE-2020-17087 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-17087), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.