Junglewise Threat Intelligence

CVE-2020-0674: Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

CVE-2020-0674 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

A remote code execution vulnerability exists in Microsoft Internet Explorer's scripting engine due to improper handling of objects in memory. An attacker could exploit this memory corruption (specifically a use-after-free) to execute arbitrary code in the context of the current user.

Affected products

  • Microsoft Internet Explorer 11
  • Microsoft Internet Explorer 10
  • Microsoft Internet Explorer 9

Timeline

  • 2020-01-17: disclosed: Initial advisory release by Microsoft
  • 2020-02-11: patched: Security updates released by Microsoft
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Confirmed as exploited in the wild per CISA KEV catalog

Related threats