CVE-2021-0674
published 2021-12-17CVE-2021-0674: In alac decoder, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional…
PriorityP423medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.51%
40.8th percentile
In alac decoder, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06064258; Issue ID: ALPS06064237.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Microsoft Internet Explorer 11 and WPAD service 'Jscript.dll' - Use-After-Free
exploitdb·2021-05-13·CVSS 7.5
CVE-2020-0674 [HIGH] Microsoft Internet Explorer 11 and WPAD service 'Jscript.dll' - Use-After-Free
Microsoft Internet Explorer 11 and WPAD service 'Jscript.dll' - Use-After-Free
---
# Exploit Title: Microsoft Internet Explorer 8/11 and WPAD service 'Jscript.dll' - Use-After-Free
# Date: 2021-05-04
# Exploit Author: deadlock (Forrest Orr)
# Vendor Homepage: https://www.microsoft.com/
# Software Link: https://www.microsoft.com/en-gb/download/internet-explorer.aspx
# Versions: IE 8-11 (64-bit) as well as the WPAD service (64-bit) on Windows 7 and 8.1 x64
# Tested on: Windows 7 x64, Windows 8.1 x64
# CVE: CVE-2020-0674
# Bypasses: DEP, ASLR, CFG
# Original (IE-only/Windows 7-only) exploit credits: maxpl0it
# Full explain chain writeup: https://github.com/forrest-orr/DoubleStar
/*
________ ___. .__ _________ __
\______ \ ____ __ __\_ |__ | | ____ / _____/_/ |_ _____ _______
| | \ / _ \ |
Exploit-DB
Microsoft Internet Explorer 11 32-bit - Use-After-Free
exploitdb·2021-02-08·CVSS 7.5
CVE-2020-0674 [HIGH] Microsoft Internet Explorer 11 32-bit - Use-After-Free
Microsoft Internet Explorer 11 32-bit - Use-After-Free
---
# Exploit Title: Microsoft Internet Explorer 11 32-bit - Use-After-Free
# Date: 2021-02-05
# Exploit Author: deadlock (Forrest Orr)
# Vendor Homepage: https://www.microsoft.com/
# Software Link: https://www.microsoft.com/en-gb/download/internet-explorer.aspx
# Version: IE 8, 9, 10, and 11
# Tested on: Windows 7 x64 and Windows 7 x86
# CVE: CVE-2020-0674
# Bypasses: DEP, ASLR, EMET 5.5 (EAF, EAF+, stack pivot protection, SimExec, CallerCheck)
# Original (64-bit) exploit credits: maxpl0it
/*
___ _ _ ___ ___ __ ___ __ __ ___ ___ _ _
/ _/| \ / || __|(_ / (_ / \ __ / \ / __|_ | || |
| \__`\ V /'| _|__/ / // / / // |__| // | ,_ \/ /`._ _|
\__/ \_/ |___||___\__/___\__/ \__/ \___/_/ |_|
Overview
This is a 32-bit re-creation of CVE-2
2021-12-17
Published