CVE-2020-0674

HIGH KEV

Microsoft Internet Explorer - Use After Free

Title source: rule

Description

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767.

Exploits (6)

exploitdb WORKING POC
by Forrest Orr · javascriptlocalwindows_x86-64
https://www.exploit-db.com/exploits/49863
exploitdb WORKING POC
by maxpl0it · textlocalwindows
https://www.exploit-db.com/exploits/49062
nomisec WORKING POC 226 stars
by maxpl0it · client-side
https://github.com/maxpl0it/CVE-2020-0674-Exploit
nomisec WORKING POC 1 stars
by Neko-chanQwQ · poc
https://github.com/Neko-chanQwQ/CVE-2020-0674-PoC
nomisec NO CODE
by Micky-Thongam · client-side
https://github.com/Micky-Thongam/Internet-Explorer-UAF
nomisec WORKING POC
by Ken-Abruzzi · client-side
https://github.com/Ken-Abruzzi/CVE-2020-0674

Scores

CVSS v3 7.5
EPSS 0.9366
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CISA KEV 2021-11-03
VulnCheck KEV 2020-02-11
InTheWild.io 2020-02-11
ENISA EUVD EUVD-2020-2167
CWE
CWE-416
Status published
Products (3)
microsoft/internet_explorer 9
microsoft/internet_explorer 10
microsoft/internet_explorer 11
Published Feb 11, 2020
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026