Junglewise Threat Intelligence

CVE-2020-0968: Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

CVE-2020-0968 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Windows Server 2008, Microsoft Windows 8.1, Microsoft Windows Server 2012, Microsoft Windows Server 2016, Microsoft Windows 10, Microsoft Windows 7, Microsoft Internet Explorer, Microsoft Windows Server 2019, Microsoft Windows Rt 8.1. Vendors: Microsoft.

Executive brief

A memory corruption vulnerability exists in the Microsoft Internet Explorer scripting engine due to improper handling of objects in memory. An attacker could exploit this to execute remote code in the context of the current user, typically requiring user interaction such as visiting a malicious website.

Affected products

  • Microsoft Internet Explorer 11 11
  • Microsoft Windows 10 1507, 1607, 1709, 1803, 1809, 1903, 1909
  • Microsoft Windows 7 SP1
  • Microsoft Windows 8.1 -
  • Microsoft Windows RT 8.1 -
  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows Server 2012 -, R2
  • Microsoft Windows Server 2016 -
  • Microsoft Windows Server 2019 -

Timeline

  • 2020-04-14: disclosed: Initial MSRC advisory and NIST analysis date.
  • 2021-11-03: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
  • 2021-11-03: other: Vulnerability published date.

Related threats