To exploit this vulnerability, a remote unauthenticated attacker could send a specially crafted request to a target system utilizing TLS 1.2 or lower, triggering the system to automatically reboot.
The update addresses the vulnerability by changing the way TLS key exchange messages are validated.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 19 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A denial of service vulnerability exists in the Windows implementation of Transport Layer Security (TLS) when it improperly handles certain key exchanges, aka 'Microsoft Windows Transport Layer Security Denial of Service Vulnerability'. | A denial of service vulnerability exists in the Windows implementation of Transport Layer Security (TLS) when it improperly handles certain key exchanges. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this vulnerability, a remote unauthenticated attacker could send a specially crafted request to a target system utilizing TLS 1.2 or lower, triggering the system to automatically reboot. The update addresses the vulnerability by changing the way TLS key exchange messages are validated. |
| Title | Microsoft Windows Transport Layer Security Denial of Service Vulnerability | |
| First Time appeared |
Microsoft windows 10 1809
Microsoft windows 10 1909 Microsoft windows Server 1803 Microsoft windows Server 1903 Microsoft windows Server 1909 |
|
| CPEs | cpe:2.3:o:microsoft:windows_10:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:arm64:* cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* cpe:2.3:o:microsoft:windows_10_1909:*:*:*:*:*:*:x86:* cpe:2.3:o:microsoft:windows_server_1803:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_1903:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_1909:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft windows 10 1809
Microsoft windows 10 1909 Microsoft windows Server 1803 Microsoft windows Server 1903 Microsoft windows Server 1909 |
|
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-08-19T16:33:39.283Z
Reserved: 2019-11-04T00:00:00.000Z
Link: CVE-2020-1118
No data.
Status : Modified
Published: 2020-05-21T23:15:15.460
Modified: 2026-08-19T17:17:20.220
Link: CVE-2020-1118
No data.
OpenCVE Enrichment
No data.