CVE-2020-0878 Details
Description
<p>A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, the attacker could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</p> <p>An attacker could host a specially crafted website that is designed to exploit the vulnerability through Microsoft browsers, and then convince a user to view the website. The attacker could also take advantage of compromised websites, or websites that accept or host user-provided content or advertisements, by adding specially crafted content that could exploit the vulnerability. In all cases, however, an attacker would have no way to force users to view the attacker-controlled content. Instead, an attacker would have to convince users to take action, typically via an enticement in email or instant message, or by getting them to open an email attachment.</p> <p>The security update addresses the vulnerability by modifying how Microsoft browsers handle objects in memory.</p>
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0878 | CISA-ADP | US Government Resource |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0878 | CVE | PatchVendor Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0878 | [email protected] | PatchVendor Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Microsoft Edge and Internet Explorer Memory Corruption Vulnerability | Nov 3, 2021 | May 3, 2022 | Apply updates per vendor instructions. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
| CWE-787 | Out-of-bounds Write | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| microsoft internet explorer | 11 - 9 |
CPE
Remediation
| |
| microsoft windows 10 1507 | All versions |
CPE
Remediation
| |
| microsoft windows 10 1607 | All versions |
CPE
Remediation
| |
| microsoft windows 10 1709 | All versions |
CPE
Remediation
| |
| microsoft windows 10 1803 | All versions |
CPE
Remediation
| |
| microsoft windows 10 1809 | All versions |
CPE
Remediation
| |
| microsoft windows 10 1903 | All versions |
CPE
Remediation
| |
| microsoft windows 10 1909 | All versions |
CPE
Remediation
| |
| microsoft windows 10 2004 | All versions |
CPE
Remediation
| |
| microsoft windows 7 | All versions |
CPE
Remediation
| |
| microsoft windows 8.1 | All versions |
CPE
Remediation
| |
| microsoft windows rt 8.1 | All versions |
CPE
Remediation
| |
| microsoft windows server 2008 | r2 sp1 |
CPE
Remediation
| |
| microsoft windows server 2012 | r2 |
CPE
Remediation
| |
| microsoft windows server 2016 | All versions |
CPE
Remediation
| |
| microsoft windows server 2019 | All versions |
CPE
Remediation
| |
| microsoft edge | All versions |
CPE
Remediation
| |
| microsoft chakracore | All versions |
CPE
Remediation
| |
Change History
18 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Feb 23, 2026 | Modified Analysis | [email protected] |
| Feb 23, 2026 | CVE Modified | [email protected] |
| Oct 29, 2025 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Mar 13, 2025 | Modified Analysis | [email protected] |
| Feb 4, 2025 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| Jul 26, 2024 | Modified Analysis | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Apr 16, 2024 | CPE Deprecation Remap | [email protected] |
| Dec 31, 2023 | CVE Modified | [email protected] |
| Jul 21, 2021 | CWE Remap | [email protected] |
| Sep 28, 2020 | CPE Deprecation Remap | [email protected] |
| Sep 17, 2020 | Initial Analysis | [email protected] |