CVE-2020-17087Active Exploitation(microsoft / windows_10_1507)

MEDIUMCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for microsoft windows_10_1507 systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Windows Kernel Local Elevation of Privilege Vulnerability

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-131

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1507
  • windows_10_1607
  • windows_10_1803
  • windows_10_1809

Threat summary

  • Active exploitation appears in 2 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-06-15); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
windows_10_1507windows_10_1607windows_10_1803windows_10_1809windows_10_1903windows_10_1909windows_10_2004windows_10_20h2windows_7windows_8.1

6 versions affected across 15 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-15: 1Mentions · 2026-06-30: 1Active Exploitation · 2026-06-15: 1Active Exploitation · 2026-06-30: 1Technical Details · 2026-06-15: 1Technical Details · 2026-06-30: 106-1506-30
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets1 URL
Full discourse2 posts
  • OS Dev@OSdev_
    Active Exploitation

    CVE-2020-17087 is a Windows kernel privilege escalation vulnerability in cng.sys. The bug is a pool buffer overflow caused by a 16-bit integer truncation in "cng!CfgAdtpFormatPropertyBlock". A crafted IOCTL ("0x390400") can cause the kernel to allocate a buffer that's too small, leading to kernel pool corruption. It was exploited in the wild as part of a Chrome sandbox escape and is an excellent case study in IOCTL handling, integer truncation, and kernel pool exploitation.

    Post summary

    CVE‑2020‑17087 is a Windows kernel privilege‑escalation flaw caused by a 16‑bit integer truncation leading to a pool buffer overflow; it has been exploited in the wild in a Chrome sandbox escape, yet no patch, PoC, or exploit code is referenced.

    18060293.2K
    5.0K followersView on X
  • OS Dev@OSdev_
    Active Exploitation

    Windows kernel bug - CVE-2020-17087 - https://googleprojectzero.github.io/0days-in-the-wild/0day-RCAs/2020/CVE-2020-17087.html The vulnerability was in the Windows Kernel Pool and boiled down to an integer truncation bug. A carefully crafted allocation caused the kernel to reserve less memory than expected, leading to a pool overflow that could corrupt neighboring objects. Attackers chained this with a browser exploit, gained arbitrary kernel read/write, and elevated themselves to SYSTEM.

    Post summary

    The post reports that CVE‑2020‑17087, an integer‑truncation kernel bug causing a pool overflow, has been actively exploited via a browser exploit to gain SYSTEM privileges.

    07034143.0K
    4.8K followersView on X
CPE platform detail34 entries

34 of 34 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1507--x64
OSmicrosoftwindows_10_1507--x86
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1803--arm64
OSmicrosoftwindows_10_1803--x64
OSmicrosoftwindows_10_1803--x86
OSmicrosoftwindows_10_1809--arm64
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_1903--arm64
OSmicrosoftwindows_10_1903--x64
OSmicrosoftwindows_10_1903--x86
OSmicrosoftwindows_10_1909--arm64
OSmicrosoftwindows_10_1909--x64
OSmicrosoftwindows_10_1909--x86
OSmicrosoftwindows_10_2004--arm64
OSmicrosoftwindows_10_2004--x64
OSmicrosoftwindows_10_2004--x86
OSmicrosoftwindows_10_20h2--arm64
OSmicrosoftwindows_10_20h2--x86
OSmicrosoftwindows_7---
OSmicrosoftwindows_8.1---
OSmicrosoftwindows_rt_8.1---
OSmicrosoftwindows_server_2008---
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_20161903--
OSmicrosoftwindows_server_20161909--
OSmicrosoftwindows_server_20162004--
OSmicrosoftwindows_server_201620h2--
OSmicrosoftwindows_server_2019---

Explore more