LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-1380: Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-1380 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user.

CVE-2020-1380 is a memory corruption vulnerability in the scripting engine of Microsoft Internet Explorer. It can allow an attacker to achieve remote code execution in the context of the current user, which means a successful exploit could run code with whatever rights that user already has on the system.

For IT and security teams, this matters because browsers and their scripting components are common entry points. Even where Internet Explorer is no longer the primary browser, it may still be present, invoked by legacy apps, or reachable via crafted content. Confirm exact scope and fixed builds against the vendor advisory.

How it works

This issue is classed as CWE-787 (out-of-bounds write), a form of memory corruption. In a scripting engine, untrusted script or related content is parsed and executed; a flaw that lets an attacker write outside the intended memory bounds can corrupt internal structures the engine relies on.

In practical terms, an attacker who can get a user to process malicious content in the affected Internet Explorer scripting path may trigger that corruption and then attempt to run arbitrary code as the logged-on user. The CISA summary describes remote code execution in the current user context; it does not require inventing specific trigger pages, heap layouts, or shellcode. Exact exploitation conditions and any prerequisites must be taken from the vendor advisory rather than assumed.

Am I affected? How to find it in your systems

Internet Explorer has historically shipped with Windows and may still appear on endpoints even when another browser is default. It can be launched directly, embedded via legacy controls, or used by internal line-of-business applications that still depend on the Trident/MSHTML stack.

Telemetry signs of exploitation are not uniquely defined in the provided facts. In general for this class, look for unexpected IE or scripting-host process crashes, unusual child processes spawned from IE-related binaries, and anomalous outbound connections shortly after browsing activity. Correlate with EDR/process creation logs and confirm any indicators against vendor or trusted threat intel rather than assuming a fixed signature set.

How to remediate

Patch first. Apply the updates Microsoft released for this vulnerability, following the vendor instructions as CISA requires. Use your standard patch deployment channel, verify installation on representative hosts, and confirm the advisory’s superseded or cumulative update guidance so you are not left on a partial fix.

If you can't patch immediately

Until the vendor update is installed, reduce exposure with compensating controls aimed at this browser/scripting class:

These steps lower risk; they do not replace the vendor update.

If your data may have been exposed

Actively exploited browser RCE vulnerabilities can lead to account takeover, malware installation, or follow-on data theft in the user context. Known ransomware use is not documented for this CVE in the provided facts, but any confirmed compromise should still be handled through your incident process: isolate hosts, reset credentials, and scope for lateral movement.

If you believe credentials or personal data may have been involved, check whether those identities appear in known breach collections. You can run a free exposure scan of your email against known breach data to see whether it has shown up in prior incidents and then proceed with password changes and monitoring as appropriate.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Internet Explorer
WeaknessCWE-787
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities