Junglewise Threat Intelligence

CVE-2020-1380: Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

CVE-2020-1380 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

A remote code execution vulnerability exists in the Microsoft Internet Explorer scripting engine due to improper handling of objects in memory. An attacker can exploit this by hosting a specially crafted website or embedding a malicious ActiveX control in an Office document, potentially gaining full user rights or administrative control.

Affected products

  • Microsoft Internet Explorer

Timeline

  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: disclosed

Related threats