CVE-2020-0738Out-of-bounds Write in Microsoft Windows

Severity
8.8HIGHNVD
EPSS
24.0%
top 3.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 11
Latest updateMay 24

Description

A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption Vulnerability'.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages10 packages

CVEListV5microsoft/windows18 versions+17
NVDmicrosoft/windows4 versions+3
NVDmicrosoft/windows_106 versions+5
CVEListV5microsoft/windows_server12 versions+11

Patches

🔴Vulnerability Details

2
GHSA
GHSA-4jr7-rvm2-mwgx: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption V2022-05-24
CVEList
CVE-2020-0738: A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory, aka 'Media Foundation Memory Corruption V2020-02-11

📋Vendor Advisories

1
Microsoft
Media Foundation Memory Corruption Vulnerability2020-02-11

🕵️Threat Intelligence

5
Tenable
Microsoft’s February 2020 Patch Tuesday Addresses 99 CVEs Including Internet Explorer Zero-Day (CVE-2020-0674)2020-02-11
Talos
Vulnerability Spotlight: Code execution vulnerability in Microsoft Media Foundation2020-02-11
Talos
Vulnerability Spotlight: Code execution vulnerability in Microsoft Media Foundation2020-02-11
Talos
Microsoft Patch Tuesday — Feb. 2020: Vulnerability disclosures and Snort coverage2020-02-11
Talos
Microsoft Patch Tuesday — Feb. 2020: Vulnerability disclosures and Snort coverage2020-02-11

💬Community

6
Bugzilla
CVE-2020-6418 chromium-browser: Type confusion in V82020-02-26
Bugzilla
CVE-2020-10531 ICU: Integer overflow in UnicodeString::doAppend()2020-02-26
Bugzilla
CVE-2020-6407 chromium-browser: Out of bounds memory access in streams2020-02-26
Bugzilla
CVE-2020-6386 chromium-browser: Use after free in speech2020-02-26
Bugzilla
CVE-2020-6384 chromium-browser: Use after free in WebAudio2020-02-26
CVE-2020-0738 — Out-of-bounds Write in Microsoft | cvebase