ZeroHour

CVE-2020-0878

KEV ransomwaremass

Memory corruption RCE in Microsoft Edge and Internet Explorer

CISA: Microsoft Edge and Internet Explorer Memory Corruption Vulnerability

CVSS 3.1
4.2 medium
EPSS
3%p85
Published
()
KEV added
AI analysis

CVE-2020-0878 is a remote code execution vulnerability caused by memory corruption (CWE-787, out-of-bounds write) in the way Microsoft browsers — Internet Explorer and Edge, listed alongside the ChakraCore JavaScript engine in the affected-product data — access objects in memory. Exploitation requires user interaction and cannot be forced: an attacker must host a specially crafted website or inject crafted content into compromised sites or sites accepting user-provided content or ads, and then entice the user to view it, typically via email or instant message. A successful attacker gains arbitrary code execution with the rights of the current user, up to full system control if the user has administrative privileges, enabling installation of programs, modification or deletion of data, and creation of new accounts. All users of the affected Microsoft browsers on Windows are in scope, per Microsoft's advisory. The flaw is confirmed exploited in the wild — it is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with known ransomware use — and EPSS estimates a 2.7% probability of exploitation in the next 30 days (85th percentile); no public PoC is known.

What to do: Apply Microsoft's security updates addressing CVE-2020-0878 for Internet Explorer and legacy Edge on all Windows systems immediately, per the CISA KEV required action, prioritizing internet-facing hosts, workstations of privileged users, and environments where ransomware use is a concern. As residual-risk mitigation, restrict or disable legacy IE/Edge browsing where feasible and migrate users to the current Chromium-based Microsoft Edge. Verify no estate segments remain unpatched — particularly extended-support Windows 7/8.1 systems and servers with Internet Explorer components — since KEV listing obligates remediation within the CISA deadline.

Affected
microsoft Internet Explorer
microsoft Edge
microsoft ChakraCore
Estimated exposure
massHundreds of millions of users/endpoints (Internet Explorer is bundled with all supported Windows versions and legacy Edge was the Windows 10 default during the… — Based on the ubiquity of the affected browsers — IE ships as an OS component across the Windows installed base and Chakra-based Edge was the default Windows 10 browser — the plausibly affected population is on the order of the entire…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, the attacker could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. An attacker could host a specially crafted website that is designed to exploit the vulnerability through Microsoft browsers, and then convince a user to view the website. The attacker could also take advantage of compromised websites, or websites that accept or host user-provided content or advertisements, by adding specially crafted content that could exploit the vulnerability. In all cases, however, an attacker would have no way to force users to view the attacker-controlled content. Instead, an attacker would have to convince users to take action, typically via an enticement in email or instant message, or by getting them to open an email attachment. The security update addresses the vulnerability by modifying how Microsoft browsers handle objects in memory.

CISA Known Exploited Vulnerability
Affected
Microsoft Edge and Internet Explorer
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
internet explorer, edge, chakracore
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.