cbcvebase.
CVE-2020-0878
published 2020-09-11

CVE-2020-0878: A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that…

PriorityP182high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
2.70%
84.2th percentile
A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, the attacker could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. An attacker could host a specially crafted website that is designed to exploit the vulnerability through Microsoft browsers, and then convince a user to view the website. The attacker could also take advantage of compromised websites, or websites that accept or host user-provided content or advertisements, by adding specially crafted content that could exploit the vulnerability. In all cases, however, an attacker would have no way to force users to view the attacker-controlled content. Instead, an attacker would have to convince users to take action, typically via an enticement in email or instant message, or by getting them to open an email attachment. The security update addresses the vulnerability by modifying how Microsoft browsers handle objects in memory.

Affected

10 ranges
VendorProductVersion rangeFixed in
microsoftchakracore< publicationpublication
microsoftinternet_explorer
microsoftinternet_explorer
microsoftinternet_explorer_11>= 1.0.0 < publicationpublication
microsoftinternet_explorer_9>= 1.0.0 < publicationpublication
microsoftmicrosoft_edge>= 1.0..0 < publicationpublication
msrcchakracore
msrcinternet_explorer_11
msrcinternet_explorer_9
msrcmicrosoft_edge

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit delivery vector is a specially crafted website; monitor for users being directed to attacker-controlled or compromised web pages via email/IM enticement or malicious attachments targeting Microsoft browsers (Edge/Internet Explorer).
  • Monitor for exploitation via compromised legitimate websites or sites hosting user-provided content/advertisements containing specially crafted content targeting Microsoft browsers.
  • Track initial access via email/IM lures or email attachments that direct victims to exploit pages in Microsoft Edge or Internet Explorer.
  • ·Exploit status as of patch release: not publicly disclosed and not exploited in the wild; exploitation assessed as 'Less Likely' for both latest and older software releases.
  • ·CISA added this to the Known Exploited Vulnerabilities catalog with a remediation due date of 2022-05-03, indicating confirmed exploitation in the wild post-disclosure.
  • ·Affected products are Microsoft Edge and Internet Explorer; the fix modifies how Microsoft browsers handle objects in memory. Ensure ChakraCore is updated to at least v1.11.22.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
vulncheck4.2MEDIUM
cisa7.5HIGH
vendor_msrc4.2MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.