CVE-2020-17053
published 2020-11-11CVE-2020-17053: Internet Explorer Memory Corruption Vulnerability Internet Explorer Memory Corruption Vulnerability
high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
2.94%
85.7th percentile
Internet Explorer Memory Corruption Vulnerability
Internet Explorer Memory Corruption Vulnerability
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | internet_explorer_11 | >= 1.0.0 < publication | publication |
| msrc | internet_explorer_11_on_windows_10_version_1803_for_32-bit_systems | — | — |
| msrc | internet_explorer_11_on_windows_10_version_1803_for_arm64-based_systems | — | — |
| msrc | internet_explorer_11_on_windows_10_version_1803_for_x64-based_systems | — | — |
| msrc | internet_explorer_11_on_windows_10_version_1809_for_32-bit_systems | — | — |
| msrc | internet_explorer_11_on_windows_10_version_1809_for_arm64-based_systems | — | — |
| msrc | internet_explorer_11_on_windows_10_version_1809_for_x64-based_systems | — | — |
| msrc | internet_explorer_11_on_windows_10_version_1903_for_32-bit_systems | — | — |
| msrc | internet_explorer_11_on_windows_10_version_1903_for_arm64-based_systems | — | — |
| msrc | internet_explorer_11_on_windows_10_version_1903_for_x64-based_systems | — | — |
| msrc | internet_explorer_11_on_windows_10_version_1909_for_32-bit_systems | — | — |
| msrc | internet_explorer_11_on_windows_10_version_1909_for_arm64-based_systems | — | — |
| msrc | internet_explorer_11_on_windows_10_version_1909_for_x64-based_systems | — | — |
| msrc | internet_explorer_11_on_windows_10_version_2004_for_32-bit_systems | — | — |
| msrc | internet_explorer_11_on_windows_10_version_2004_for_arm64-based_systems | — | — |
| msrc | internet_explorer_11_on_windows_10_version_2004_for_x64-based_systems | — | — |
| msrc | internet_explorer_11_on_windows_10_version_20h2_for_32-bit_systems | — | — |
| msrc | internet_explorer_11_on_windows_10_version_20h2_for_arm64-based_systems | — | — |
| msrc | internet_explorer_11_on_windows_server_2019 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
cvelistv57.5HIGH
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Internet Explorer Memory Corruption Vulnerability
vendor_msrc·2020-11-10·CVSS 7.5
CVE-2020-17053 [HIGH] Internet Explorer Memory Corruption Vulnerability
Internet Explorer Memory Corruption Vulnerability
Microsoft Scripting Engine: Microsoft Scripting Engine
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely;Older Software Release:Exploitation More Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4586785
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4586793
Reference: https://support.microsoft.com/help/4586793
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4586786
Reference: https://support.microsoft.com/help/4586786
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4586781
Reference: https:/
CVEList
Internet Explorer Memory Corruption Vulnerability
cvelistv5·2020-11-11·CVSS 7.5
CVE-2020-17053 [HIGH] Internet Explorer Memory Corruption Vulnerability
Internet Explorer Memory Corruption Vulnerability
Internet Explorer Memory Corruption Vulnerability
Project0
Project Zero RCA: CVE-2020-1380: Internet Explorer JScript9 Use-after-Free
project_zero·CVSS 7.8
CVE-2020-1380 [HIGH] Project Zero RCA: CVE-2020-1380: Internet Explorer JScript9 Use-after-Free
# CVE-2020-1380: Internet Explorer JScript9 Use-after-Free
*Maddie Stone & Samuel Groß, Project Zero (Originally posted on [Project Zero blog](https://googleprojectzero.blogspot.com/p/rca.html) 2020-08-24)*
## The Basics
**Disclosure or Patch Date:** 11 August 2020
**Product:** Microsoft Internet Explorer
**Advisory:** https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1380
**Affected Versions:** For Windows 10 2004, [KB4565503](https://support.microsoft.com/en-us/help/4565503/windows-10-update-kb4565503) and previous
**First Patched Version:** For Windows 10 2004, [KB4566782](https://support.microsoft.com/en-us/help/4566782/windows-10-update-kb4566782)
**Issue/Bug Report:** N/A
**Patch CL:** N/A
**Bug-Introducing CL:** N/A
**Reporter(s):** Boris Larin (
No detection rules found.
No public exploits indexed.
Trendmicro
This Week in Security News
blogs_trendmicro·2020-11-19·CVSS 7.8
[HIGH] This Week in Security News
# This Week in Security News - November 19
Cybercrime Moves to the Cloud to Accelerate Attacks Amid Data Glut and Trend Micro Announces Free Web-Based Tool
By: Jon Clay
2020/11/19
Read time: ( words)
Save to Folio
Read on:
Attackers Are Using the Cloud, Too. Here’s What You Need to Know.
In a sample dataset of 1,000 logs, Trend Micro identified a total of 67,712 URLs for compromised accounts. Access to these so called “Cloud of Logs” can be purchased for a monthly fee between $350-$1,000 and can include thousands or millions of emails and passwords to popular sites like Google, Amazon, Twitter, Facebook and PayPal.
Cybercrime Moves to the Cloud to Accelerate Attacks Amid Data Glut
Cybercriminals are embracing cloud-based services and technologies in order to accelerate their attac
Trendmicro
CVE-2020-17053: Use-After-Free IE Vulnerability
blogs_trendmicro·2020-11-17·CVSS 7.8
CVE-2020-17053 [HIGH] CVE-2020-17053: Use-After-Free IE Vulnerability
Exploits & Vulnerabilities
## CVE-2020-17053: Use-After-Free IE Vulnerability
We analyze how CVE-2020-17053 was found and how it works.
By: Elliot Cao Nov 17, 2020 Read time: ( words)
Save to Folio
In my previous blog titled CVE-2020-1380: Analysis of Recently Fixed IE Zero-Day , I discussed how that vulnerability was caused by a type inference error in the browser’s JIT engine, which can be exploited by neutering ArrayBuffer and resulted in a use-after-free (UAF) vulnerability. While analyzing the root cause of this vulnerability, I found another path to trigger a similar UAF vulnerability by neutering ArrayBuffer — but this time, without the need for the JIT engine. This bug was submitted to Microsoft in September via the Zero-Day Initiative and fixed in November’s Patch Tuesday as
Trendmicro
CVE-2020-17053: Use-After-Free IE Vulnerability
blogs_trendmicro·2020-11-17·CVSS 7.8
CVE-2020-17053 [HIGH] CVE-2020-17053: Use-After-Free IE Vulnerability
Exploits & Vulnerabilities
# CVE-2020-17053: Use-After-Free IE Vulnerability
We analyze how CVE-2020-17053 was found and how it works.
By: Elliot Cao
2020/11/17
Read time: ( words)
Save to Folio
In my previous blog titled CVE-2020-1380: Analysis of Recently Fixed IE Zero-Day, I discussed how that vulnerability was caused by a type inference error in the browser’s JIT engine, which can be exploited by neutering ArrayBuffer and resulted in a use-after-free (UAF) vulnerability. While analyzing the root cause of this vulnerability, I found another path to trigger a similar UAF vulnerability by neutering ArrayBuffer — but this time, without the need for the JIT engine. This bug was submitted to Microsoft in September via the Zero-Day Initiative and fixed in November’s Patch Tuesday as CVE
Trendmicro
CVE-2020-17053: Use-After-Free IE Vulnerability
blogs_trendmicro·2020-11-17·CVSS 7.8
CVE-2020-17053 [HIGH] CVE-2020-17053: Use-After-Free IE Vulnerability
Exploits y vulnerabilidades
## CVE-2020-17053: Use-After-Free IE Vulnerability
We analyze how CVE-2020-17053 was found and how it works.
By: Elliot Cao Nov 17, 2020 Read time: ( words)
Save to Folio
In my previous blog titled CVE-2020-1380: Analysis of Recently Fixed IE Zero-Day , I discussed how that vulnerability was caused by a type inference error in the browser’s JIT engine, which can be exploited by neutering ArrayBuffer and resulted in a use-after-free (UAF) vulnerability. While analyzing the root cause of this vulnerability, I found another path to trigger a similar UAF vulnerability by neutering ArrayBuffer — but this time, without the need for the JIT engine. This bug was submitted to Microsoft in September via the Zero-Day Initiative and fixed in November’s Patch Tuesday as
Trendmicro
CVE-2020-17053: Use-After-Free IE Vulnerability
blogs_trendmicro·2020-11-17·CVSS 7.8
CVE-2020-17053 [HIGH] CVE-2020-17053: Use-After-Free IE Vulnerability
Exploits & Vulnerabilities
## CVE-2020-17053: Use-After-Free IE Vulnerability
We analyze how CVE-2020-17053 was found and how it works.
By: Elliot Cao 2020/11/17 Read time: ( words)
Save to Folio
In my previous blog titled CVE-2020-1380: Analysis of Recently Fixed IE Zero-Day , I discussed how that vulnerability was caused by a type inference error in the browser’s JIT engine, which can be exploited by neutering ArrayBuffer and resulted in a use-after-free (UAF) vulnerability. While analyzing the root cause of this vulnerability, I found another path to trigger a similar UAF vulnerability by neutering ArrayBuffer — but this time, without the need for the JIT engine. This bug was submitted to Microsoft in September via the Zero-Day Initiative and fixed in November’s Patch Tuesday as CV
Trendmicro
CVE-2020-17053: Use-After-Free IE Vulnerability
blogs_trendmicro·2020-11-17·CVSS 7.8
CVE-2020-17053 [HIGH] CVE-2020-17053: Use-After-Free IE Vulnerability
Sfruttamento vulnerabilità
## CVE-2020-17053: Use-After-Free IE Vulnerability
We analyze how CVE-2020-17053 was found and how it works.
By: Elliot Cao Nov 17, 2020 Read time: ( words)
Save to Folio
In my previous blog titled CVE-2020-1380: Analysis of Recently Fixed IE Zero-Day , I discussed how that vulnerability was caused by a type inference error in the browser’s JIT engine, which can be exploited by neutering ArrayBuffer and resulted in a use-after-free (UAF) vulnerability. While analyzing the root cause of this vulnerability, I found another path to trigger a similar UAF vulnerability by neutering ArrayBuffer — but this time, without the need for the JIT engine. This bug was submitted to Microsoft in September via the Zero-Day Initiative and fixed in November’s Patch Tuesday as
Trendmicro
CVE-2020-17053: Use-After-Free IE Vulnerability
blogs_trendmicro·2020-11-17·CVSS 7.8
CVE-2020-17053 [HIGH] CVE-2020-17053: Use-After-Free IE Vulnerability
Ausnutzung von Schwachstellen
## CVE-2020-17053: Use-After-Free IE Vulnerability
We analyze how CVE-2020-17053 was found and how it works.
By: Elliot Cao Nov 17, 2020 Read time: ( words)
Save to Folio
In my previous blog titled CVE-2020-1380: Analysis of Recently Fixed IE Zero-Day , I discussed how that vulnerability was caused by a type inference error in the browser’s JIT engine, which can be exploited by neutering ArrayBuffer and resulted in a use-after-free (UAF) vulnerability. While analyzing the root cause of this vulnerability, I found another path to trigger a similar UAF vulnerability by neutering ArrayBuffer — but this time, without the need for the JIT engine. This bug was submitted to Microsoft in September via the Zero-Day Initiative and fixed in November’s Patch Tuesday
Trendmicro
November Patch Tuesday Fixes Exchange, NFS Vulns
blogs_trendmicro·2020-11-11·CVSS 9.6
[CRITICAL] November Patch Tuesday Fixes Exchange, NFS Vulns
Exploits & Vulnerabilities
# November Patch Tuesday Fixes Exchange, NFS Vulns
Comparing to last month’s update, which saw a noticeable drop to over 80 fixes, the total number of patches for this month increased again, with over a hundred patches released.
By: Trend Micro
2020/11/11
Read time: ( words)
Save to Folio
Microsoft’s Patch Tuesday for November had 112 patches, with 17 categorized as critical. Compared to last month’s update, which saw a noticeable drop to over 80 fixes, the total number of patches for this month increased again, with over a hundred patches released. Six of the vulnerabilities came through the Zero Day Initiative program. Details on the patches can be viewed on Microsoft’s Security Update Guide page.
Patch for recently disclosed zero-day CVE-2020-17087
Thi
Zscaler
Zscaler protects against 9 new vulnerabilities for Microsoft
blogs_zscaler·CVSS 7.0
[HIGH] Zscaler protects against 9 new vulnerabilities for Microsoft
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
2020-11-11
Published