CVE-2020-1064

HIGH

Internet Explorer - Remote Code Execution via MSHTML Engine Input Validation

Title source: llm
STIX 2.1

Description

A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input.An attacker could execute arbitrary code in the context of the current user, aka 'MSHTML Engine Remote Code Execution Vulnerability'.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0717
EPSS Percentile 93.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

Status published
Products (2)
microsoft/internet_explorer 9
microsoft/internet_explorer 11
Published May 21, 2020
Tracked Since Feb 18, 2026