CVE-2020-0878
published 2020-09-11CVE-2020-0878: A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that…
PriorityP182high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
2.70%
84.2th percentile
A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, the attacker could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
An attacker could host a specially crafted website that is designed to exploit the vulnerability through Microsoft browsers, and then convince a user to view the website. The attacker could also take advantage of compromised websites, or websites that accept or host user-provided content or advertisements, by adding specially crafted content that could exploit the vulnerability. In all cases, however, an attacker would have no way to force users to view the attacker-controlled content. Instead, an attacker would have to convince users to take action, typically via an enticement in email or instant message, or by getting them to open an email attachment.
The security update addresses the vulnerability by modifying how Microsoft browsers handle objects in memory.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | chakracore | < publication | publication |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer_11 | >= 1.0.0 < publication | publication |
| microsoft | internet_explorer_9 | >= 1.0.0 < publication | publication |
| microsoft | microsoft_edge | >= 1.0..0 < publication | publication |
| msrc | chakracore | — | — |
| msrc | internet_explorer_11 | — | — |
| msrc | internet_explorer_9 | — | — |
| msrc | microsoft_edge | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit delivery vector is a specially crafted website; monitor for users being directed to attacker-controlled or compromised web pages via email/IM enticement or malicious attachments targeting Microsoft browsers (Edge/Internet Explorer). ↗
- →Monitor for exploitation via compromised legitimate websites or sites hosting user-provided content/advertisements containing specially crafted content targeting Microsoft browsers. ↗
- →Track initial access via email/IM lures or email attachments that direct victims to exploit pages in Microsoft Edge or Internet Explorer. ↗
- ·Exploit status as of patch release: not publicly disclosed and not exploited in the wild; exploitation assessed as 'Less Likely' for both latest and older software releases. ↗
- ·CISA added this to the Known Exploited Vulnerabilities catalog with a remediation due date of 2022-05-03, indicating confirmed exploitation in the wild post-disclosure. ↗
- ·Affected products are Microsoft Edge and Internet Explorer; the fix modifies how Microsoft browsers handle objects in memory. Ensure ChakraCore is updated to at least v1.11.22. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
vulncheck4.2MEDIUM
cisa7.5HIGH
vendor_msrc4.2MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6j33-6rqj-fh2m: A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vul
ghsa_unreviewed·2022-05-24
CVE-2020-0878 [HIGH] CWE-787 GHSA-6j33-6rqj-fh2m: A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vul
A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'.
VulnCheck
Microsoft Edge and Internet Explorer Memory Corruption Vulnerability
vulncheck·2020·CVSS 4.2
CVE-2020-0878 [MEDIUM] CWE-787 Microsoft Edge and Internet Explorer Memory Corruption Vulnerability
Microsoft Edge and Internet Explorer Memory Corruption Vulnerability
Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user.
Affected: Microsoft Edge and Internet Explorer
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-05-03
CISA
Microsoft Edge and Internet Explorer Memory Corruption Vulnerability
cisa·2021-11-03·CVSS 7.5
CVE-2020-0878 [HIGH] CWE-787 Microsoft Edge and Internet Explorer Memory Corruption Vulnerability
Vulnerability: Microsoft Edge and Internet Explorer Memory Corruption Vulnerability
Affected: Microsoft Edge and Internet Explorer
Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-0878
Remediation Due Date: 2022-05-03
Microsoft
Microsoft Browser Memory Corruption Vulnerability
vendor_msrc·2020-09-08·CVSS 4.2
CVE-2020-0878 [MEDIUM] Microsoft Browser Memory Corruption Vulnerability
Microsoft Browser Memory Corruption Vulnerability
Description: A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, the attacker could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
An attacker could host a specially crafted website that is designed to exploit the vulnerability through Microsoft browsers, and then convince
No detection rules found.
No public exploits indexed.
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
blogs_qualys·2022-02-23
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
#### Table of Contents
- Situation
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISA Vulnerabilities Using Qualys VMDR
- CISA Exploited RTI
- Detailed Operational Dashboard
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
CISA released a directive in November 2021, recommending urgent and prioritized remediation of actively exploited vulnerabilities. Both government agencies and corporations should heed this advice. This blog outlines how Qualys Vulnerability Management, Detection & Response can be used by any organization to respond to this directive efficiently and effectively.
## Situation
Last November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directiv
Tenable
Microsoft’s September 2020 Patch Tuesday Addresses 129 CVEs
blogs_tenable·2020-09-08
Microsoft’s September 2020 Patch Tuesday Addresses 129 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
2020-09-11
Published
2021-11-03
Added to CISA KEV
Exploited in the wild