cbcvebase.
CVE-2020-0640
published 2020-01-14

CVE-2020-0640: A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption…

PriorityP183high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
8.17%
94.2th percentile
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka 'Internet Explorer Memory Corruption Vulnerability'.

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftinternet_explorer
microsoftinternet_explorer
microsoftinternet_explorer
microsoftinternet_explorer_10
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is triggered when Internet Explorer improperly accesses objects in memory via a specially crafted website; monitor for IE process spawning unexpected child processes or executing arbitrary code in user context
  • Attack vector includes malicious email attachments or links delivered via email/instant message leading to IE memory corruption; monitor for IE launched from email clients or messaging applications
  • The vulnerable component is the Microsoft Scripting Engine within Internet Explorer; focus detection on scripting engine activity (e.g., jscript.dll, vbscript.dll) under iexplore.exe process
  • Compromised or attacker-controlled websites injecting specially crafted content are a delivery vector; monitor web proxy logs for IE user-agent requests to newly registered or low-reputation domains
  • ·Exploit status at time of advisory was 'Exploitation Less Likely' for both latest and older software releases, and not yet publicly disclosed or exploited in the wild; prioritize patching over active threat hunting unless context changes
  • ·The fix modifies how Internet Explorer handles objects in memory; unpatched systems running IE with the Microsoft Scripting Engine remain at risk regardless of user privilege level, but administrative users face full system compromise

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vulncheck7.5HIGH
vendor_msrc6.4MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.