LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-0878: Microsoft Edge and Internet Explorer Memory Corruption Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-0878 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user.

CVE-2020-0878 is a memory corruption vulnerability in Microsoft Edge and Internet Explorer that can let an attacker run code in the context of the signed-in user. Because these browsers are common on Windows endpoints and the flaw has been tied to ransomware activity, unpatched systems raise the risk of compromise through ordinary web browsing or crafted content. Confirm exact product builds and fixed releases against the Microsoft advisory.

How it works

The weakness is classified as CWE-787 (out-of-bounds write). In this class of flaw, the browser mishandles memory so that data can be written outside the intended buffer. An attacker who can deliver specially crafted web content or other input processed by the vulnerable browser component may trigger the corruption. Successful abuse can lead to arbitrary code execution under the privileges of the current user, which on a typical desktop may still allow further actions such as installing malware, stealing tokens, or moving laterally if the user has elevated rights or access to sensitive resources. Exact trigger conditions and exploit mechanics are not detailed here; treat any public proof-of-concept claims cautiously and verify against the vendor advisory.

Am I affected? How to find it in your systems

Microsoft Edge (legacy/EdgeHTML era) and Internet Explorer are the affected products. These browsers commonly appear on Windows workstations, terminal servers, kiosks, and some application hosts that still embed or launch IE/Edge components for compatibility.

How to remediate

Patch first. Apply the Microsoft updates that address CVE-2020-0878 exactly as described in the vendor advisory and follow CISA’s required action to apply updates per vendor instructions. Use your standard patch-management process to deploy the relevant cumulative or security updates to all affected Windows systems, then verify installation.

If you can't patch immediately

Until the vendor update can be applied, reduce risk with compensating controls focused on this browser memory-corruption class.

If your data may have been exposed

Actively exploited vulnerabilities, including those with known ransomware use, frequently lead to credential theft, malware deployment, or broader breaches. If you suspect compromise, isolate affected hosts, preserve forensic data, reset credentials for the impacted user context, and follow your incident-response plan. You can also run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in public breach corpora and then prioritize password changes and multifactor authentication accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Edge and Internet Explorer
WeaknessCWE-787
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities