EXPOSURES › CVE-2020-0968
CVE-2020-0968
HIGH ⌖ ON CISA KEV · EXPLOITEDA memory corruption flaw in Internet Explorer's Scripting Engine allowed remote code execution, and was actively exploited in the wild.
Microsoft Internet Explorer contained a memory corruption vulnerability in its Scripting Engine that enabled remote code execution. This flaw was listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating it was actively exploited in the wild. DIB organizations must ensure legacy browsers are patched or disabled, as unpatched IE remains a high-risk attack vector for ransomware and data breaches.
Shame score — A known memory corruption vulnerability in a widely deployed legacy browser was actively exploited in the wild, demonstrating severe negligence in patch management and reliance on obsolete software.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution.
"Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution."
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |