CVE-2020-1567
published 2020-08-17CVE-2020-1567: A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker could execute arbitrary code in the…
PriorityP346high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
3.67%
88.4th percentile
A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input.
An attacker could execute arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
In a HTML editing attack scenario, an attacker could trick a user into editing a specially crafted file that is designed to exploit the vulnerability.
The security update addresses the vulnerability by modifying how MSHTML engine validates input.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer_11 | >= 1.0.0 < publication | publication |
| microsoft | internet_explorer_9 | >= 1.0.0 < publication | publication |
| msrc | internet_explorer_11 | — | — |
| msrc | internet_explorer_9 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ffgx-6737-mpr2: A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input
ghsa_unreviewed·2022-05-24
CVE-2020-1567 [HIGH] CWE-20 GHSA-ffgx-6737-mpr2: A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input
A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input.An attacker could execute arbitrary code in the context of the current user, aka 'MSHTML Engine Remote Code Execution Vulnerability'.
Microsoft
MSHTML Engine Remote Code Execution Vulnerability
vendor_msrc·2020-08-11·CVSS 7.5
CVE-2020-1567 [MEDIUM] MSHTML Engine Remote Code Execution Vulnerability
MSHTML Engine Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input.
An attacker could execute arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
In a HTML editing attack scenario, an attacker could trick a user into editing a specially crafted file that is designed to exploit the vulnerability.
The security update addresses the vulnerability by modifying how MSHTML engine validates input.
Internet Explorer: Int
No detection rules found.
No public exploits indexed.
Checkpoint
17th August – Threat Intelligence Bulletin
blogs_checkpoint·2020-08-17
CVE-2020-1380 17th August – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 17th August – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 17th August 2020, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
The SANS information security training institute has suffered a data breach comprised of 27,000 records of PII (Personally Identifiable Information) which were forwarded to an external email address. SANS traced the source of the attack to a phishing email.
The city of Lafayette Colorado has fallen victim to a ranso
Trendmicro
Patch Tuesday: Fixes for Important Vulnerabilities
blogs_trendmicro·2020-08-11·CVSS 7.8
[HIGH] Patch Tuesday: Fixes for Important Vulnerabilities
Exploits & Vulnerabilities
# Patch Tuesday: Fixes for Important Vulnerabilities
The August batch of Patch Tuesday updates includes 120 updates for the Microsoft suite, with 17 fixes rated as Critical, and the remaining 103 ranked as Important. ZDI disclosed 11 flaws, five of which are rated critical bugs.
By: Trend Micro
2020/08/11
Read time: ( words)
Save to Folio
Update on 08/19/2020 09:55AM PHT: Added rules for Trend Micro Deep Security.
The August batch of Patch Tuesday updates includes 120 updates for the Microsoft suite, with 17 fixes rated as Critical, and the remaining 103 ranked as Important. CVE-2020-1380 is a critical Internet Explorer (IE) vulnerability that can be abused for remote code execution (RCE), while CVE-2020-1464 is a Windows 10 security gap that can be used f
Zscaler
Zscaler found New Security Vulnerabilities | 8-11-2020
blogs_zscaler·CVSS 7.8
[HIGH] Zscaler found New Security Vulnerabilities | 8-11-2020
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Bugzilla
CVE-2019-19074 kernel: a memory leak in the ath9k management function in allows local DoS
bugzilla·2019-11-21·CVSS 7.5
CVE-2019-19074 [HIGH] CVE-2019-19074 kernel: a memory leak in the ath9k management function in allows local DoS
CVE-2019-19074 kernel: a memory leak in the ath9k management function in allows local DoS
A memory leak in the Atheros Wireless Module Interface (WMI) function (ath9k_wmi_cmd) in in the Linux kernel through 5.3.11 allows a local attacker, who has permissions to issue wifi device access control to cause a denial of service (memory consumption).
Upstream Reference:
https://github.com/torvalds/linux/commit/728c1e2a05e4b5fc52fab3421dce772a806612a2
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1774934]
---
At this time it is understood that this flaw does not qualify kernel-rt or mrg-2 fixes due to the current product lifecycle.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:1567 https://acces
2020-08-17
Published