PT-2020-4156 · Microsoft · Internet Explorer+1
Published
2020-09-08
·
Updated
2023-12-31
·
CVE-2020-16884
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Internet Explorer (affected versions not specified)
Microsoft Edge (affected versions not specified)
Description:
A remote code execution issue exists due to the way the IEToEdge Browser Helper Object (BHO) plugin handles objects in memory, potentially allowing an attacker to execute arbitrary code in the context of the current user. This could be exploited through a web-based attack scenario where an attacker hosts a specially crafted website designed to exploit this issue. The attacker would need to convince a user to view the website, typically by getting them to click a link or open an attachment. If the current user has administrative rights, a successful exploit could allow the attacker to take control of the affected system, enabling them to install programs, view, change, or delete data, or create new accounts with full user rights.
Recommendations:
For Internet Explorer, update the IEToEdge BHO plug-in to modify how it handles objects in memory.
For Microsoft Edge, update the browser to address the vulnerability in the IEToEdge Browser Helper Object (BHO) plugin.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Internet Explorer
Edge