LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-0674: Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-0674 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Internet Explorer contains a memory corruption vulnerability due to the way the Scripting Engine handles objects in memory. Successful exploitation could allow remote code execution in the…

How it works

CVE-2020-0674 is a memory corruption vulnerability in the Scripting Engine of Microsoft Internet Explorer. It is classified as CWE-416 (use-after-free). In this class of flaw, the engine mishandles objects in memory so that a reference to freed memory can still be used. An attacker who can cause the browser to process specially crafted content can corrupt memory state and potentially achieve remote code execution in the security context of the logged-on user.

Public detail on exact trigger mechanics is limited; defenders should treat any untrusted web content or embedded script that reaches the Internet Explorer scripting engine as a possible vector. Successful exploitation would run code with the privileges of the current user, not automatically as SYSTEM, but that is still enough to install further malware, steal data, or move laterally if the user has elevated rights or access to sensitive resources. Confirm all technical specifics against the vendor advisory.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Internet Explorer. Internet Explorer may still be present on Windows endpoints even when Microsoft Edge is the default browser, and it can be invoked by legacy applications, ActiveX controls, group-policy settings, or file-type associations. Inventory every Windows workstation and server that still has the Internet Explorer components installed or enabled.

How to remediate

Patch first. Apply the security updates Microsoft released for this vulnerability, following the vendor instructions exactly. CISA’s required action is to apply updates per vendor instructions. After patching, verify the update is present on every affected host via your patch-management console or by checking the relevant knowledge-base article listed in the advisory.

If you can't patch immediately

If immediate patching is impossible, reduce exposure with compensating controls until the update can be deployed.

If your data may have been exposed

Actively exploited browser vulnerabilities can lead to endpoint compromise and subsequent data theft. Known ransomware use of this specific CVE is not documented, but any successful remote-code-execution event should be treated as a potential breach. Isolate affected hosts, collect memory and disk evidence, reset credentials for the impacted user, and hunt for lateral movement. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Internet Explorer
WeaknessCWE-416
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities