Junglewise Threat Intelligence

CVE-2020-0878: Microsoft Edge and Internet Explorer Memory Corruption Vulnerability

CVE-2020-0878 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Edge, Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

A memory corruption vulnerability in Microsoft Edge and Internet Explorer allows remote code execution when a user visits a specially crafted website. An attacker could execute arbitrary code in the context of the current user, potentially gaining full administrative rights if the user is logged in with such privileges.

Affected products

  • Microsoft Edge
  • Microsoft Internet Explorer

Timeline

  • 2021-11-03: disclosed
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2021-11-03: exploited

Related threats