CVE-2020-14979Active Exploitation(evga / precision_x1)

MEDIUMCVSS 7.8 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Prioritize remediation for evga precision_x1 systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The WinRing0.sys and WinRing0x64.sys drivers 1.2.0 in EVGA Precision X1 through 1.0.6 allow local users, including low integrity processes, to read and write to arbitrary memory locations. This allows any user to gain NT AUTHORITY\SYSTEM privileges by mapping \Device\PhysicalMemory into the calling process.

4.0/ 10 priority

Sources & remediation

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • precision_x1
  • winring0

Threat summary

  • Active exploitation appears in 4 classified signals
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 4 signals
  • Technical details provided in 4 signals
  • General: 1 classified signal
  • False Positive: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-02-23); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Products
precision_x1winring0

1 version affected across 2 products

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-02-23: 3Mentions · 2026-02-24: 1Mentions · 2026-05-23: 1Mentions · 2026-06-25: 1Active Exploitation · 2026-02-23: 3Active Exploitation · 2026-02-24: 1Technical Details · 2026-02-23: 2Technical Details · 2026-02-24: 1Technical Details · 2026-05-23: 102-2302-2405-2306-25
Signal classification3 categories
Active Exploitation
466.7%
General
116.7%
False Positive
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-233
Active Exploitation3
2026-02-241
Active Exploitation1
2026-05-231
General1
2026-06-251
False Positive1
Full discourse6 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    ⚠️ Researchers uncovered a cryptojacking campaign hiding in pirated software bundles 🏴‍☠️ It drops a custom XMRig miner and abuses a flawed driver (CVE-2020-14979) to boost hashrate by 15–50%. It can spread via USB drives, even into air-gapped systems. 🔗 Details → https://thehackernews.com/2026/02/wormable-xmrig-campaign-uses-byovd.html

    Post summary

    Researchers report that CVE-2020-14979 is being actively exploited in a cryptojacking campaign that spreads via USB drives and targets air‑gapped systems, boosting miner hashrate.

    33801042510.9K
    1.0M followersView on X
  • blanche 🫧@angelroom0
    General

    @troy0h1 Feel free to research those yourself, and next time don't make me do it for you CVE-2024-1460, CVE-2020-14979, CVE-2020-8808, CVE-2025-9870, CVE-2018-8061, CVE-2025-65264, CVE-2019-25360, CVE-2020-5990 None of these are false flags, all of these are LPEs or Kernel R/W :) https://t.co/EnrQU9rrGa

    Post summary

    The tweet lists several CVEs identified as LPEs or kernel read/write, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    100511.1K
    3.1K followersView on X
  • vehbi duman@VehbiDuman
    False Positive

    @Orkanos @Orkanos Hi, sorry for replying here. I got a false positive ban on Division 2. ASUS USA officially confirmed that their software (GameFirst) created the file GameTurbo.sys (CVE-2020-14979), triggering EAC. Please check Case #25783760 / Account: Mr.wiNst10 https://t.co/ZKhWghisPB

    Post summary

    The tweet indicates a false‑positive ban caused by ASUS GameFirst creating GameTurbo.sys, which falsely triggered EAC—no real exploitation or technical details are provided.

    50000168
    135 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Active Exploitation

    A wormable XMRig cryptojacking campaign exploits BYOVD via WinRing0x64.sys (CVE-2020-14979), uses modular binaries, spreads through removable media, and includes a 2025 logic bomb. Linked to React2Shell & ILOVEPOOP. #XMRigMiner #LogicBomb #USA https://ift.tt/DJ9GIyv

    Post summary

    The post reports that CVE-2020-14979 is being actively exploited in a wormable XMRig cryptojacking campaign that spreads via removable media and includes a logic bomb.

    00010142
    3.6K followersView on X
  • IT news for all 🇺🇦@IT_news_for_all
    Active Exploitation

    ⚠️ Researchers uncovered a cryptojacking campaign hiding in pirated software bundles 🏴‍☠️ It drops a custom XMRig miner and abuses a flawed driver (CVE-2020-14979) to boost hashrate by 15–50%. It can spread via USB drives, even into air-gapped syste... https://t.me/s/it_news_for_all/89570

    Post summary

    Researchers uncovered a cryptojacking campaign that exploits CVE‑2020‑14979 via a flawed driver to boost mining performance, spreading through USB drives even to air‑gapped systems.

    0000037
    388 followersView on X
  • IT news for all 🇺🇦@IT_news_for_all
    Active Exploitation

    ⚠️ Researchers uncovered a cryptojacking campaign hiding in pirated software bundles 🏴‍☠️ It drops a custom XMRig miner and abuses a flawed driver (CVE-2020-14979) to boost hashrate by 15–50%. It can spread via USB drives, even into air-gapped syste... https://t.me/s/it_news_for_all/8468

    Post summary

    Researchers uncovered a cryptojacking campaign that exploits CVE‑2020‑14979 via a flawed driver, spreading through USB drives and boosting mining performance by 15–50%.

    0000040
    388 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appevgaprecision_x1---
Appwinring0_projectwinring01.2.0--

Explore more