EXPOSURES › CVE-2020-0878
CVE-2020-0878
CRITICAL ⌖ ON CISA KEV · EXPLOITEDMicrosoft Edge and Internet Explorer suffered a memory corruption vulnerability exploited in ransomware attacks, allowing code execution with user privileges.
A memory corruption flaw in Microsoft Edge and Internet Explorer enabled attackers to execute code as the current user, potentially leading to ransomware infection and significant compliance impact for DIB organizations; ensure timely patching and vulnerability scanning.
Shame score — The vulnerability's exploitation in ransomware attacks highlights a serious failure in Microsoft's security practices and poses a significant risk to DIB organizations.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user.
"Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user."
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |