peter bassill · operator
$ cve CVE-2020-0878 JSON

CVE-2020-0878 KEV

4.2
MEDIUM · CVSS 3.1 · EPSS 2.7% (pctl 85)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-03.

Description

<p>A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, the attacker could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</p> <p>An attacker could host a specially crafted website that is designed to exploit the vulnerability through Microsoft browsers, and then convince a user to view the website. The attacker could also take advantage of compromised websites, or websites that accept or host user-provided content or advertisements, by adding specially crafted content that could exploit the vulnerability. In all cases, however, an attacker would have no way to force users to view the attacker-controlled content. Instead, an attacker would have to convince users to take action, typically via an enticement in email or instant message, or by getting them to open an email attachment.</p> <p>The security update addresses the vulnerability by modifying how Microsoft browsers handle objects in memory.</p>

Scoring

CVSS4.2 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
EPSS2.7% — more likely to be exploited than 85% of all CVEs
WeaknessCWE-787
On CISA KEVyes — remediate by 2022-05-03
Public exploitnone known
Published2020-09-11
Last modified2026-06-17

CISA KEV

NameMicrosoft Edge and Internet Explorer Memory Corruption Vulnerability
Added2021-11-03
Due2022-05-03
Vendor / productMicrosoft / Edge and Internet Explorer
Ransomware useknown

Affected (18)

VendorProduct
microsoftchakracore
microsoftedge
microsoftinternet explorer
microsoftwindows 10 1507
microsoftwindows 10 1607
microsoftwindows 10 1709
microsoftwindows 10 1803
microsoftwindows 10 1809
microsoftwindows 10 1903
microsoftwindows 10 1909
microsoftwindows 10 2004
microsoftwindows 7
microsoftwindows 8.1
microsoftwindows rt 8.1
microsoftwindows server 2008
microsoftwindows server 2012
microsoftwindows server 2016
microsoftwindows server 2019

References

→ the Explorer  ·  watch your stack  ·  NVD