Skip to content
COOEY

EXPOSURES › CVE-2020-0878

CVE-2020-0878

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-0878 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwareexploited-in-wildunpatched

Microsoft Edge and Internet Explorer suffered a memory corruption vulnerability exploited in ransomware attacks, allowing code execution with user privileges.

A memory corruption flaw in Microsoft Edge and Internet Explorer enabled attackers to execute code as the current user, potentially leading to ransomware infection and significant compliance impact for DIB organizations; ensure timely patching and vulnerability scanning.

Shame score — The vulnerability's exploitation in ransomware attacks highlights a serious failure in Microsoft's security practices and poses a significant risk to DIB organizations.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.80
Critical vulnerability in widely used browsers poses significant security risk to enterprise environments.
cooey ↗ severe-fallout -0.80
Critical vulnerability in widely used browsers poses significant security risk to enterprise environments.
"Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user."
AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized