PT-2020-1389 · Microsoft · Internet Explorer
Published
2020-01-17
·
Updated
2025-08-18
·
CVE-2020-0674
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Internet Explorer versions 9 through 11
Description
A remote code execution issue exists due to incorrect handling of objects in memory by the scripting engine in Internet Explorer. This could allow an attacker to execute arbitrary code in the context of the current user, potentially leading to a takeover of the affected system if the user has administrative rights.
Recommendations
For Internet Explorer versions 9 through 11, consider temporarily restricting access to JScript.dll as a mitigation measure until a patch is available.
Restrict access to Internet Explorer to minimize the risk of exploitation, especially for users operating with administrative privileges.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Buffer Overflow
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Explorer