Rapid7 Vulnerability & Exploit Database

Microsoft CVE-2020-0711: Scripting Engine Memory Corruption Vulnerability

Free InsightVM Trial No Credit Card Necessary
Watch Demo See how it all works
Back to Search

Microsoft CVE-2020-0711: Scripting Engine Memory Corruption Vulnerability

Severity
8
CVSS
(AV:N/AC:H/Au:N/C:C/I:C/A:C)
Published
02/11/2020
Created
02/12/2020
Added
02/11/2020
Modified
11/18/2021

Description

A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0674, CVE-2020-0710, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767.

Solution(s)

  • msft-kb4532691-0e78339f-1546-434c-85f1-ec5617eb15b2
  • msft-kb4532691-d959bd97-3c54-40d0-8100-6d302772e599
  • msft-kb4532691-e34e7c64-e906-423c-8e30-7a79d1d0c745
  • msft-kb4532693-0b4acda9-369c-4ffd-b1ec-792428aff755
  • msft-kb4532693-2af89f5f-4888-4c15-87a0-467219280044
  • msft-kb4532693-5f59add0-ba47-42c3-af2a-9aa334c053bb
  • msft-kb4532693-a9b1a21b-4d78-4445-a122-0920a6bed52a
  • msft-kb4532693-bb723d9d-43f9-41c3-ac36-25a6146ee6e3
  • msft-kb4532693-caec06fd-2ec3-455a-a38c-206eae8f2e18
  • msft-kb4537762-21b1dad8-3ca4-4890-884c-5312344085c5
  • msft-kb4537762-8e02820e-88cd-4d1a-bd06-02a6ae14e6a5
  • msft-kb4537762-d31c92db-ef15-475c-a50c-ee0f3b03888e

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;