CVE-2020-0847
published 2020-03-12CVE-2020-0847: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.
PriorityP347high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
7.75%
94.0th percentile
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11_on_windows_10_version_1903_for_32-bit_systems | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vendor_msrc6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
VBScript Remote Code Execution Vulnerability
vendor_msrc·2020-03-10·CVSS 6.4
CVE-2020-0847 [HIGH] VBScript Remote Code Execution Vulnerability
VBScript Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exp
GHSA
GHSA-w885-p3mm-52qg: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulner
ghsa_unreviewed·2022-05-24
CVE-2020-0847 [HIGH] CWE-119 GHSA-w885-p3mm-52qg: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulner
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'.
No detection rules found.
No public exploits indexed.
Trendmicro
Patch Tuesday: LNK, Microsoft Word, SMBv3 Gets Patched
blogs_trendmicro·2020-03-11·CVSS 8.8
[HIGH] Patch Tuesday: LNK, Microsoft Word, SMBv3 Gets Patched
Exploits & Vulnerabilities
## Patch Tuesday: LNK, Microsoft Word, SMBv3 Gets Patched
March Patch Tuesday tackles a total of 115 vulnerabilities. 26 were identified as Critical, 88 deemed Important, and one was classified as Moderate. None of this month’s listed vulnerabilities were exploited in the wild before being patched.
By: Trend Micro 2020/03/11 Read time: ( words)
Save to Folio
Updated on March 12, 2020, 10:30 P.M. Eastern time with information about the SMBv3 vulnerability.
Following the unexpectedly long list of fixes included in last month ’s Patch Tuesday, March brings an even longer one, albeit less eventful. A total of 115 vulnerabilities were fixed, 26 of which were identified as Critical as they could lead to remote code execution (RCE). 88 were classified as Important
Trendmicro
Patch Tuesday: LNK, Microsoft Word, SMBv3 Gets Patched
blogs_trendmicro·2020-03-11·CVSS 8.8
[HIGH] Patch Tuesday: LNK, Microsoft Word, SMBv3 Gets Patched
Ausnutzung von Schwachstellen
## Patch Tuesday: LNK, Microsoft Word, SMBv3 Gets Patched
March Patch Tuesday tackles a total of 115 vulnerabilities. 26 were identified as Critical, 88 deemed Important, and one was classified as Moderate. None of this month’s listed vulnerabilities were exploited in the wild before being patched.
By: Trend Micro Mar 11, 2020 Read time: ( words)
Save to Folio
Updated on March 12, 2020, 10:30 P.M. Eastern time with information about the SMBv3 vulnerability.
Following the unexpectedly long list of fixes included in last month ’s Patch Tuesday, March brings an even longer one, albeit less eventful. A total of 115 vulnerabilities were fixed, 26 of which were identified as Critical as they could lead to remote code execution (RCE). 88 were classified as Impo
Trendmicro
Patch Tuesday: LNK, Microsoft Word, SMBv3 Gets Patched
blogs_trendmicro·2020-03-11·CVSS 8.8
[HIGH] Patch Tuesday: LNK, Microsoft Word, SMBv3 Gets Patched
Exploits y vulnerabilidades
## Patch Tuesday: LNK, Microsoft Word, SMBv3 Gets Patched
March Patch Tuesday tackles a total of 115 vulnerabilities. 26 were identified as Critical, 88 deemed Important, and one was classified as Moderate. None of this month’s listed vulnerabilities were exploited in the wild before being patched.
By: Trend Micro Mar 11, 2020 Read time: ( words)
Save to Folio
Updated on March 12, 2020, 10:30 P.M. Eastern time with information about the SMBv3 vulnerability.
Following the unexpectedly long list of fixes included in last month ’s Patch Tuesday, March brings an even longer one, albeit less eventful. A total of 115 vulnerabilities were fixed, 26 of which were identified as Critical as they could lead to remote code execution (RCE). 88 were classified as Import
Trendmicro
Patch Tuesday: LNK, Microsoft Word, SMBv3 Gets Patched
blogs_trendmicro·2020-03-11·CVSS 8.8
[HIGH] Patch Tuesday: LNK, Microsoft Word, SMBv3 Gets Patched
Exploits & Vulnerabilities
# Patch Tuesday: LNK, Microsoft Word, SMBv3 Gets Patched
March Patch Tuesday tackles a total of 115 vulnerabilities. 26 were identified as Critical, 88 deemed Important, and one was classified as Moderate. None of this month’s listed vulnerabilities were exploited in the wild before being patched.
By: Trend Micro
2020/03/11
Read time: ( words)
Save to Folio
Updated on March 12, 2020, 10:30 P.M. Eastern time with information about the SMBv3 vulnerability.
Following the unexpectedly long list of fixes included in last month’s Patch Tuesday, March brings an even longer one, albeit less eventful. A total of 115 vulnerabilities were fixed, 26 of which were identified as Critical as they could lead to remote code execution (RCE). 88 were classified as Important
Trendmicro
Patch Tuesday: LNK, Microsoft Word, SMBv3 Gets Patched
blogs_trendmicro·2020-03-11·CVSS 8.8
[HIGH] Patch Tuesday: LNK, Microsoft Word, SMBv3 Gets Patched
Sfruttamento vulnerabilità
## Patch Tuesday: LNK, Microsoft Word, SMBv3 Gets Patched
March Patch Tuesday tackles a total of 115 vulnerabilities. 26 were identified as Critical, 88 deemed Important, and one was classified as Moderate. None of this month’s listed vulnerabilities were exploited in the wild before being patched.
By: Trend Micro Mar 11, 2020 Read time: ( words)
Save to Folio
Updated on March 12, 2020, 10:30 P.M. Eastern time with information about the SMBv3 vulnerability.
Following the unexpectedly long list of fixes included in last month ’s Patch Tuesday, March brings an even longer one, albeit less eventful. A total of 115 vulnerabilities were fixed, 26 of which were identified as Critical as they could lead to remote code execution (RCE). 88 were classified as Importa
Trendmicro
Patch Tuesday: LNK, Microsoft Word, SMBv3 Gets Patched
blogs_trendmicro·2020-03-11·CVSS 8.8
[HIGH] Patch Tuesday: LNK, Microsoft Word, SMBv3 Gets Patched
Exploits & Vulnerabilities
## Patch Tuesday: LNK, Microsoft Word, SMBv3 Gets Patched
March Patch Tuesday tackles a total of 115 vulnerabilities. 26 were identified as Critical, 88 deemed Important, and one was classified as Moderate. None of this month’s listed vulnerabilities were exploited in the wild before being patched.
By: Trend Micro Mar 11, 2020 Read time: ( words)
Save to Folio
Updated on March 12, 2020, 10:30 P.M. Eastern time with information about the SMBv3 vulnerability.
Following the unexpectedly long list of fixes included in last month ’s Patch Tuesday, March brings an even longer one, albeit less eventful. A total of 115 vulnerabilities were fixed, 26 of which were identified as Critical as they could lead to remote code execution (RCE). 88 were classified as Importa
Talos
Microsoft Patch Tuesday — March 2020: Vulnerability disclosures and Snort coverage
blogs_talos·2020-03-10·CVSS 8.8
CVE-2020-0796 [HIGH] Microsoft Patch Tuesday — March 2020: Vulnerability disclosures and Snort coverage
By Jon Munshaw and Vitor Ventura.
Update (March 12, 2020): Microsoft released an out-of-band patch for CVE-2020-0796, a code execution vulnerability SMB client and server for Windows. An unauthenticated attacker could exploit this vulnerability to execute remote code. Snort rules 53425 - 53428 protect against exploitation of CVE-2020-0796.
Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 117 vulnerabilities, 25 of which are considered critical. There is also one moderate vulnerability and 91 that are considered important.
This month's patches include updates to Microsoft Media Foundation, the GDI+ API and Windows Defender, among others.
Talos released a new
Talos
Microsoft Patch Tuesday — March 2020: Vulnerability disclosures and Snort coverage
blogs_talos·2020-03-10·CVSS 8.8
CVE-2020-0796 [HIGH] Microsoft Patch Tuesday — March 2020: Vulnerability disclosures and Snort coverage
## Microsoft Patch Tuesday — March 2020: Vulnerability disclosures and Snort coverage
By Jon Munshaw and Vitor Ventura.
Update (March 12, 2020): Microsoft released an out-of-band patch for CVE-2020-0796, a code execution vulnerability SMB client and server for Windows. An unauthenticated attacker could exploit this vulnerability to execute remote code. Snort rules 53425 - 53428 protect against exploitation of CVE-2020-0796.
Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 117 vulnerabilities, 25 of which are considered critical. There is also one moderate vulnerability and 91 that are considered important.
This month's patches include updates to Microsoft M
Tenable
Microsoft’s March 2020 Patch Tuesday Addresses 115 CVEs, Including 58 Elevation of Privilege Flaws
blogs_tenable·2020-03-10
Microsoft’s March 2020 Patch Tuesday Addresses 115 CVEs, Including 58 Elevation of Privilege Flaws
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Zscaler
Zscaler found New Security Vulnerabilities | 10-03-2020
blogs_zscaler·CVSS 10.0
[CRITICAL] Zscaler found New Security Vulnerabilities | 10-03-2020
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
2020-03-12
Published