CVE-2020-0738
published 2020-02-11CVE-2020-0738: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption…
high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'.
Affected
63 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1903_for_32-bit_systems | — | — |
GHSA
GHSA-4jr7-rvm2-mwgx: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption V
ghsa_unreviewed·2022-05-24
CVE-2020-0738 [HIGH] CWE-119 GHSA-4jr7-rvm2-mwgx: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption V
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'.
Microsoft
Media Foundation Memory Corruption Vulnerability
vendor_msrc·2020-02-11·CVSS 8.8
CVE-2020-0738 [HIGH] Media Foundation Memory Corruption Vulnerability
Media Foundation Memory Corruption Vulnerability
Description: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights.
There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit a malicious webpage.
The security update addresses the vulnerability by correcting how Windows Media Foundation handles objects in memory.
Windows Media: Windows Media
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Expl
No detection rules found.
No public exploits indexed.
Tenable
Microsoft’s February 2020 Patch Tuesday Addresses 99 CVEs Including Internet Explorer Zero-Day (CVE-2020-0674)
blogs_tenable·2020-02-11·CVSS 7.5
[HIGH] Microsoft’s February 2020 Patch Tuesday Addresses 99 CVEs Including Internet Explorer Zero-Day (CVE-2020-0674)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Talos
Vulnerability Spotlight: Code execution vulnerability in Microsoft Media Foundation
blogs_talos·2020-02-11·CVSS 8.8
[HIGH] Vulnerability Spotlight: Code execution vulnerability in Microsoft Media Foundation
Marcin Noga of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
Microsoft Media Foundation’s framework contains a code execution vulnerability. This specific bug lies in Media Foundations’ MPEG4 DLL. An attacker could provide a user with a specially crafted ASF file to exploit this vulnerability. Microsoft disclosed this vulnerability in this month’s Patch Tuesday. For
more on the updates Microsoft released, read Talos’ full blog here.
In accordance with our coordinated disclosure policy, Cisco Talos worked with Microsoft to ensure that these issues are resolved and that an update is available for affected customers.
### Vulnerability detailsMicrosoft Media Foundation IMFASFSplitter::Initialize code execution vulnerability (TALOS-2019-0946/CVE-2020-0738)
An exploitable
Talos
Vulnerability Spotlight: Code execution vulnerability in Microsoft Media Foundation
blogs_talos·2020-02-11·CVSS 8.8
[HIGH] Vulnerability Spotlight: Code execution vulnerability in Microsoft Media Foundation
## Vulnerability Spotlight: Code execution vulnerability in Microsoft Media Foundation
Marcin Noga of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
Microsoft Media Foundation’s framework contains a code execution vulnerability. This specific bug lies in Media Foundations’ MPEG4 DLL. An attacker could provide a user with a specially crafted ASF file to exploit this vulnerability. Microsoft disclosed this vulnerability in this month’s Patch Tuesday. For
more on the updates Microsoft released, read Talos’ full blog here .
In accordance with our coordinated disclosure policy, Cisco Talos worked with Microsoft to ensure that these issues are resolved and that an update is available for affected customers.
## Vulnerability details Microsoft Media Foundation IMFASFSplitter:
Talos
Microsoft Patch Tuesday — Feb. 2020: Vulnerability disclosures and Snort coverage
blogs_talos·2020-02-11·CVSS 8.8
[HIGH] Microsoft Patch Tuesday — Feb. 2020: Vulnerability disclosures and Snort coverage
By Jon Munshaw.
Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 98 vulnerabilities, 12 of which are considered critical and 84 that are considered important. There are also two bugs that were not assigned a severity.
This month's patches include updates to the Windows kernel, the Windows scripting engine and Remote Desktop Procol, among other software and features. Microsoft also provided a critical advisory covering updates to Adobe Flash Player.
Talos released a new set of SNORTⓇ rules today that provide coverage for some of these vulnerabilities, which you can see here.
### Critical vulnerabilities Microsoft disclosed 12 critical vulnerabilities this mo
Talos
Microsoft Patch Tuesday — Feb. 2020: Vulnerability disclosures and Snort coverage
blogs_talos·2020-02-11·CVSS 7.5
[HIGH] Microsoft Patch Tuesday — Feb. 2020: Vulnerability disclosures and Snort coverage
## Microsoft Patch Tuesday — Feb. 2020: Vulnerability disclosures and Snort coverage
By Jon Munshaw.
Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 98 vulnerabilities, 12 of which are considered critical and 84 that are considered important. There are also two bugs that were not assigned a severity.
This month's patches include updates to the Windows kernel, the Windows scripting engine and Remote Desktop Procol, among other software and features. Microsoft also provided a critical advisory covering updates to Adobe Flash Player.
Talos released a new set of SNORTⓇ rules today that provide coverage for some of these vulnerabilities, which you can see here
Bugzilla
CVE-2020-6418 chromium-browser: Type confusion in V8
bugzilla·2020-02-26·CVSS 8.8
CVE-2020-6418 [HIGH] CVE-2020-6418 chromium-browser: Type confusion in V8
CVE-2020-6418 chromium-browser: Type confusion in V8
Type confusion in V8
Discussion:
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop_24.html
---
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1807357]
Affects: fedora-all [bug 1807356]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0738 https://access.redhat.com/errata/RHSA-2020:0738
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6418
Bugzilla
CVE-2020-10531 ICU: Integer overflow in UnicodeString::doAppend()
bugzilla·2020-02-26·CVSS 8.8
CVE-2020-10531 [HIGH] CVE-2020-10531 ICU: Integer overflow in UnicodeString::doAppend()
CVE-2020-10531 ICU: Integer overflow in UnicodeString::doAppend()
Integer overflow in ICU
Discussion:
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop_24.html
---
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1807359]
Affects: fedora-all [bug 1807358]
---
Chromium bug: https://bugs.chromium.org/p/chromium/issues/detail?id=1044570 (private)
Upstream ICU bug: https://unicode-org.atlassian.net/browse/ICU-20958 (private)
Upstream pull request: https://github.com/unicode-org/icu/pull/971
Upstream patch: https://github.com/unicode-org/icu/commit/b7d08bc04a4296982fcef8b6b8a354a9e4e7afca
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0738 htt
Bugzilla
CVE-2020-6407 chromium-browser: Out of bounds memory access in streams
bugzilla·2020-02-26·CVSS 8.8
CVE-2020-6407 [HIGH] CVE-2020-6407 chromium-browser: Out of bounds memory access in streams
CVE-2020-6407 chromium-browser: Out of bounds memory access in streams
Out of bounds memory access in streams.
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1807383]
Affects: fedora-all [bug 1807382]
---
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop_24.html
---
*** Bug 1807341 has been marked as a duplicate of this bug. ***
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0738 https://access.redhat.com/errata/RHSA-2020:0738
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6407
Bugzilla
CVE-2020-6386 chromium-browser: Use after free in speech
bugzilla·2020-02-26·CVSS 8.8
CVE-2020-6386 [HIGH] CVE-2020-6386 chromium-browser: Use after free in speech
CVE-2020-6386 chromium-browser: Use after free in speech
An use after free flaw was found in the speech component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1043603
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop_18.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1807504]
Affects: fedora-all [bug 1807503]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0738 https://access.redhat.com/errata/RHSA-2020:0738
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6386
Bugzilla
CVE-2020-6384 chromium-browser: Use after free in WebAudio
bugzilla·2020-02-26·CVSS 8.8
CVE-2020-6384 [HIGH] CVE-2020-6384 chromium-browser: Use after free in WebAudio
CVE-2020-6384 chromium-browser: Use after free in WebAudio
An use after free flaw was found in the WebAudio component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1048473
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop_18.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1807504]
Affects: fedora-all [bug 1807503]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0738 https://access.redhat.com/errata/RHSA-2020:0738
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6384
Bugzilla
CVE-2020-6383 chromium-browser: Type confusion in V8
bugzilla·2020-02-26·CVSS 8.8
CVE-2020-6383 [HIGH] CVE-2020-6383 chromium-browser: Type confusion in V8
CVE-2020-6383 chromium-browser: Type confusion in V8
A type confusion flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1051017
External References:
https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop_18.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1807504]
Affects: fedora-all [bug 1807503]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:0738 https://access.redhat.com/errata/RHSA-2020:0738
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6383
2020-02-11
Published