A denial of service vulnerability exists in the Windows implementation of Transport Layer Security (TLS) when it improperly handles certain key exchanges. An attacker who successfully exploited the vulnerability could cause a target system to stop responding.
To exploit this vulnerability, a remote unauthenticated attacker could send a specially crafted request to a target system utilizing TLS 1.2 or lower, triggering the system to automatically reboot.
The update addresses the vulnerability by changing the way TLS key exchange messages are validated.
References
| Link | Resource |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-1118 | |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1118 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2020-05-21 23:15
Updated : 2026-08-19 17:17
NVD link : CVE-2020-1118
Mitre link : CVE-2020-1118
CVE.ORG link : CVE-2020-1118
JSON object : View
Products Affected
microsoft
- windows_server_2019
- windows_10
CWE
