CVE-2020-17052
published 2020-11-11CVE-2020-17052: Scripting Engine Memory Corruption Vulnerability Scripting Engine Memory Corruption Vulnerability
high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
2.46%
82.7th percentile
Scripting Engine Memory Corruption Vulnerability
Scripting Engine Memory Corruption Vulnerability
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | internet_explorer_11 | >= 1.0.0 < publication | publication |
| microsoft | microsoft_edge | >= 1.0..0 < publication | publication |
| msrc | internet_explorer_11 | — | — |
| msrc | microsoft_edge | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
cvelistv57.5HIGH
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Scripting Engine Memory Corruption Vulnerability
vendor_msrc·2020-11-10·CVSS 7.5
CVE-2020-17052 [HIGH] Scripting Engine Memory Corruption Vulnerability
Scripting Engine Memory Corruption Vulnerability
Microsoft Scripting Engine: Microsoft Scripting Engine
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely;Older Software Release:Exploitation More Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4586785
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4586793
Reference: https://support.microsoft.com/help/4586793
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4586786
Reference: https://support.microsoft.com/help/4586786
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4586781
Reference: https://
CVEList
Scripting Engine Memory Corruption Vulnerability
cvelistv5·2020-11-11·CVSS 7.5
CVE-2020-17052 [HIGH] Scripting Engine Memory Corruption Vulnerability
Scripting Engine Memory Corruption Vulnerability
Scripting Engine Memory Corruption Vulnerability
No detection rules found.
No public exploits indexed.
Trendmicro
November Patch Tuesday Fixes Exchange, NFS Vulns
blogs_trendmicro·2020-11-11·CVSS 9.6
[CRITICAL] November Patch Tuesday Fixes Exchange, NFS Vulns
Exploits & Vulnerabilities
# November Patch Tuesday Fixes Exchange, NFS Vulns
Comparing to last month’s update, which saw a noticeable drop to over 80 fixes, the total number of patches for this month increased again, with over a hundred patches released.
By: Trend Micro
2020/11/11
Read time: ( words)
Save to Folio
Microsoft’s Patch Tuesday for November had 112 patches, with 17 categorized as critical. Compared to last month’s update, which saw a noticeable drop to over 80 fixes, the total number of patches for this month increased again, with over a hundred patches released. Six of the vulnerabilities came through the Zero Day Initiative program. Details on the patches can be viewed on Microsoft’s Security Update Guide page.
Patch for recently disclosed zero-day CVE-2020-17087
Thi
Talos
Microsoft Patch Tuesday for Nov. 2020 — Snort rules and prominent vulnerabilities
blogs_talos·2020-11-10·CVSS 8.8
[HIGH] Microsoft Patch Tuesday for Nov. 2020 — Snort rules and prominent vulnerabilities
By Jon Munshaw, with contributions from Joe Marshall.
Microsoft released its monthly security update Tuesday, disclosing just over 110 vulnerabilities across its products. This is a slight jump from last month when Microsoft disclosed one of their lowest vulnerability totals in months.
Eighteen of the vulnerabilities are considered “critical" while the vast remainder are ranked as “important,” with two also considered of “low” importance. Users of all Microsoft and Windows products are urged to update their software as soon as possible to avoid possible exploitation of all these bugs.
The security updates cover several different products and services, including the HEVC video file extension, the Azure Sphere platform and Microsoft Exchange servers.
Talos also released a new set of SNOR
Talos
Microsoft Patch Tuesday for Nov. 2020 — Snort rules and prominent vulnerabilities
blogs_talos·2020-11-10·CVSS 8.8
[HIGH] Microsoft Patch Tuesday for Nov. 2020 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for Nov. 2020 — Snort rules and prominent vulnerabilities
By Jon Munshaw, with contributions from Joe Marshall.
Microsoft released its monthly security update Tuesday, disclosing just over 110 vulnerabilities across its products. This is a slight jump from last month when Microsoft disclosed one of their lowest vulnerability totals in months .
Eighteen of the vulnerabilities are considered “critical" while the vast remainder are ranked as “important,” with two also considered of “low” importance. Users of all Microsoft and Windows products are urged to update their software as soon as possible to avoid possible exploitation of all these bugs.
The security updates cover several different products and services, including the HEVC video file extension, the Azure
2020-11-11
Published