Umbra Wiki cve cve/CVE-2020-0674
Back to wiki

CVE-2020-0674 — Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

provenance: imported · CVE: CVE-2020-0674

CVE-2020-0674: Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Microsoft
Product Internet Explorer
Date added 2021-11-03
Due date 2022-05-03
Ransomware campaign use Unknown

Description

Microsoft Internet Explorer contains a memory corruption vulnerability due to the way the Scripting Engine handles objects in memory. Successful exploitation could allow remote code execution in the context of the current user.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2020-0674

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2020-0674
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog