Remote Code Execution Vulnerability in Microsoft ChakraCore Scripting Engine
CVE-2020-0711

7.5HIGH

What is CVE-2020-0711?

A vulnerability exists in the way the ChakraCore scripting engine manages objects in memory, which could allow an attacker to execute arbitrary code on a target system. This weakness arises due to improper handling of certain objects, leading to memory corruption. Successful exploitation may enable an attacker to gain control of the affected system, potentially allowing for unauthorized access and manipulation of sensitive data. Keeping ChakraCore updated and applying the latest security patches is crucial to safeguard systems against potential threats.

Affected Version(s)

ChakraCore = unspecified

Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1803 for 32-bit Systems = unspecified

Microsoft Edge (EdgeHTML-based) on Windows 10 Version 1803 for ARM64-based Systems = unspecified

References

EPSS Score

10% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.