
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-1074 is a remote code execution vulnerability in the Windows Jet Database Engine that was discovered in 2019 and disclosed in 2020. The vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, affecting various versions of Microsoft Windows including Windows 10 and Windows 7 SP1 (NVD).
The vulnerability stems from improper handling of objects in memory by the Windows Jet Database Engine. It has been assigned a CVSS v3.1 base score of 7.8 (HIGH) with the vector string CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating local access is required but no privileges are needed, though user interaction is required (NVD).
If successfully exploited, this vulnerability allows an attacker to execute arbitrary code on a victim system. The high CVSS score indicates potential severe impacts on system confidentiality, integrity, and availability (NVD).
An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The attack requires user interaction but does not require elevated privileges for execution (NVD).
Microsoft has released an update that addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory. Users are advised to apply the security update to affected systems (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."