CVE-2020-0674

HIGH KEV

Microsoft Internet Explorer - Use After Free

Title source: rule

Description

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767.

Exploits (6)

nomisec WORKING POC 226 stars
by maxpl0it · client-side
https://github.com/maxpl0it/CVE-2020-0674-Exploit
nomisec WORKING POC 1 stars
by Neko-chanQwQ · poc
https://github.com/Neko-chanQwQ/CVE-2020-0674-PoC
nomisec WORKING POC
by Ken-Abruzzi · client-side
https://github.com/Ken-Abruzzi/CVE-2020-0674
nomisec NO CODE
by Micky-Thongam · client-side
https://github.com/Micky-Thongam/Internet-Explorer-UAF
exploitdb WORKING POC
by Forrest Orr · javascriptlocalwindows_x86-64
https://www.exploit-db.com/exploits/49863
exploitdb WORKING POC
by maxpl0it · textlocalwindows
https://www.exploit-db.com/exploits/49062

Scores

CVSS v3 7.5
EPSS 0.9364
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Exploitation Intel

CISA KEV 2021-11-03
VulnCheck KEV 2020-02-11
InTheWild.io 2020-02-11
ENISA EUVD EUVD-2020-2167

Classification

CWE
CWE-416
Status published

Affected Products (3)

microsoft/internet_explorer
microsoft/internet_explorer
microsoft/internet_explorer

Timeline

Published Feb 11, 2020
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026