PT-2023-7064 · Microsoft · Windows Scripting Engine+3

Published

2023-11-14

·

Updated

2024-05-29

·

CVE-2023-36017

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows Scripting Engine (affected versions not specified)
Description The issue is related to a memory corruption vulnerability in the Windows Scripting Engine, specifically with the jscript9.dll dynamic library. This vulnerability can be exploited by remote attackers, potentially allowing them to execute arbitrary code and affect the system. The exploitation is associated with a buffer overflow in memory when processing the jscript9.dll library.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Type Confusion

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2023-08089
CVE-2023-36017

Affected Products

Internet Explorer
Windows
Windows Scripting Engine
Jscript9.Dll