CVE-2020-1459

An information disclosure vulnerability exists on ARM implementations that use speculative execution in control flow via a side-channel analysis, aka "straight-line speculation." To exploit this vulnerability, an attacker with local privileges would need to run a specially crafted application. The security update addresses the vulnerability by bypassing the speculative execution.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10:1903:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10:1909:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10:2004:*:*:*:*:*:*:*

History

23 Feb 2026, 18:25

Type Values Removed Values Added
Summary (en) An information disclosure vulnerability exists on ARM implementations that use speculative execution in control flow via a side-channel analysis, aka "straight-line speculation." To exploit this vulnerability, an attacker with local privileges would need to run a specially crafted application. The security update addresses the vulnerability by bypassing the speculative execution. (en) An information disclosure vulnerability exists on ARM implementations that use speculative execution in control flow via a side-channel analysis, aka "straight-line speculation." To exploit this vulnerability, an attacker with local privileges would need to run a specially crafted application. The security update addresses the vulnerability by bypassing the speculative execution.

21 Nov 2024, 05:10

Type Values Removed Values Added
References () https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1459 - Patch, Vendor Advisory () https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1459 - Patch, Vendor Advisory

19 Jan 2024, 00:15

Type Values Removed Values Added
Summary <p>An information disclosure vulnerability exists on ARM implementations that use speculative execution in control flow via a side-channel analysis, aka &quot;straight-line speculation.&quot;</p> <p>To exploit this vulnerability, an attacker with local privileges would need to run a specially crafted application.</p> <p>The security update addresses the vulnerability by bypassing the speculative execution.</p> An information disclosure vulnerability exists on ARM implementations that use speculative execution in control flow via a side-channel analysis, aka &quot;straight-line speculation.&quot; To exploit this vulnerability, an attacker with local privileges would need to run a specially crafted application. The security update addresses the vulnerability by bypassing the speculative execution.

04 Jan 2024, 02:15

Type Values Removed Values Added
CVSS v2 : 2.1
v3 : 5.5
v2 : 2.1
v3 : 7.5
Summary An information disclosure vulnerability exists on ARM implementations that use speculative execution in control flow via a side-channel analysis, aka &quot;straight-line speculation, aka 'Windows ARM Information Disclosure Vulnerability'. <p>An information disclosure vulnerability exists on ARM implementations that use speculative execution in control flow via a side-channel analysis, aka &quot;straight-line speculation.&quot;</p> <p>To exploit this vulnerability, an attacker with local privileges would need to run a specially crafted application.</p> <p>The security update addresses the vulnerability by bypassing the speculative execution.</p>

Information

Published : 2020-08-17 19:15

Updated : 2026-02-23 18:25


NVD link : CVE-2020-1459

Mitre link : CVE-2020-1459

CVE.ORG link : CVE-2020-1459


JSON object : View

Products Affected

microsoft

  • windows_10
CWE
CWE-203

Observable Discrepancy