cbcvebase.
CVE-2020-0968
published 2020-04-15

CVE-2020-0968: A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory…

PriorityP183high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
30.02%
98.0th percentile
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0970.

Affected

19 ranges
VendorProductVersion rangeFixed in
microsoftchakracore< 1.11.181.11.18
microsoftchakracore
microsoftinternet_explorer
microsoftinternet_explorer
microsoftmicrosoft_edge_on_windows_10_version_1803_for_32-bit_systems
microsoftmicrosoft_edge_on_windows_10_version_1803_for_arm64-based_systems
microsoftmicrosoft_edge_on_windows_10_version_1803_for_x64-based_systems
microsoftmicrosoft_edge_on_windows_10_version_1809_for_32-bit_systems
microsoftmicrosoft_edge_on_windows_10_version_1809_for_arm64-based_systems
microsoftmicrosoft_edge_on_windows_10_version_1809_for_x64-based_systems
microsoftmicrosoft_edge_on_windows_10_version_1903_for_32-bit_systems
microsoftmicrosoft_edge_on_windows_10_version_1903_for_arm64-based_systems
microsoftmicrosoft_edge_on_windows_10_version_1903_for_x64-based_systems
microsoftmicrosoft_edge_on_windows_10_version_1909_for_32-bit_systems
microsoftmicrosoft_edge_on_windows_10_version_1909_for_arm64-based_systems
microsoftmicrosoft_edge_on_windows_10_version_1909_for_x64-based_systems
microsoftmicrosoft_edge_on_windows_server_2019
msrcinternet_explorer_11
msrcinternet_explorer_9

Detection & IOCsextracted from sources · hover to see the quote

  • Attack vector is web-based: attacker hosts a specially crafted website targeting Internet Explorer's scripting engine to trigger memory corruption and achieve RCE
  • Attack can also be delivered via ActiveX control marked 'safe for initialization' embedded in an application or Microsoft Office document hosting the IE rendering engine — monitor for IE rendering engine invocations from Office processes
  • Compromised or malicious websites serving user-provided content or advertisements are a delivery vector — monitor IE for navigation to untrusted/ad-serving domains triggering scripting engine activity
  • Exploitation results in code execution as the current user; if the user has admin rights, full system takeover is possible — monitor for unexpected child processes spawned by iexplore.exe or processes hosting the IE rendering engine
  • Microsoft rates exploitation as 'More Likely' for both latest and older software releases — prioritize detection on unpatched IE instances across all supported Windows versions
  • CVE-2020-0968 is a critical Internet Explorer scripting engine flaw — the advisory was revised to indicate no confirmed in-the-wild exploitation at patch time, but exploitation was assessed as likely soon after disclosure
  • ·The vulnerability is in the scripting engine's handling of objects in memory within Internet Explorer specifically — ChakraCore (CVE-2020-0970) is a distinct, separate CVE and should not be conflated with CVE-2020-0968
  • ·The affected component is the Microsoft Scripting Engine within Internet Explorer — patches are delivered via multiple KB articles (KB4550951, KB4550905, KB4550922, KB4549949, KB4550927, KB4550930, KB4550929, KB4550964, KB4550961, KB4550917)

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
ghsa7.5HIGH
osv7.5HIGH
vulncheck7.5HIGH
cisa7.5HIGH
vendor_msrc6.4MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.