9.3

CVE-2020-1073

A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Edge Version -
   Microsoft ≫ Windows 10 Version -
   Microsoft ≫ Windows 10 Version 1607
   Microsoft ≫ Windows 10 Version 1709
   Microsoft ≫ Windows 10 Version 1803
   Microsoft ≫ Windows 10 Version 1809
   Microsoft ≫ Windows 10 Version 1903
   Microsoft ≫ Windows 10 Version 1909
   Microsoft ≫ Windows Server 2016 Version -
   Microsoft ≫ Windows Server 2019 Version -
Microsoft ≫ Chakracore Version < 1.11.20
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.64% 0.944
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1073
Patch
Vendor Advisory