7.6
CVE-2020-1567
- EPSS 3.67%
- Veröffentlicht 17.08.2020 19:15:20
- Zuletzt bearbeitet 23.02.2026 18:25:40
- Erkennungen
MSHTML Engine Remote Code Execution Vulnerability
A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker could execute arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. In a HTML editing attack scenario, an attacker could trick a user into editing a specially crafted file that is designed to exploit the vulnerability. The security update addresses the vulnerability by modifying how MSHTML engine validates input.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Internet Explorer Version 11 Update -
Microsoft ≫ Windows 10 Version - HwPlatform x64
Microsoft ≫ Windows 10 Version - HwPlatform x86
Microsoft ≫ Windows 10 Version 1607 HwPlatform x64
Microsoft ≫ Windows 10 Version 1607 HwPlatform x86
Microsoft ≫ Windows 10 Version 1709
Microsoft ≫ Windows 10 Version 1803
Microsoft ≫ Windows 10 Version 1809
Microsoft ≫ Windows 10 Version 1903
Microsoft ≫ Windows 10 Version 1909
Microsoft ≫ Windows 10 Version 2004
Microsoft ≫ Windows 7 Version - Update sp1
Microsoft ≫ Windows 8.1 Version -
Microsoft ≫ Windows Rt 8.1 Version -
Microsoft ≫ Windows Server 2012 Version -
Microsoft ≫ Windows Server 2012 Version r2
Microsoft ≫ Windows Server 2016
Microsoft ≫ Windows Server 2019 Version -
Microsoft ≫ Windows 10 Version - HwPlatform x86
Microsoft ≫ Windows 10 Version 1607 HwPlatform x64
Microsoft ≫ Windows 10 Version 1607 HwPlatform x86
Microsoft ≫ Windows 10 Version 1709
Microsoft ≫ Windows 10 Version 1803
Microsoft ≫ Windows 10 Version 1809
Microsoft ≫ Windows 10 Version 1903
Microsoft ≫ Windows 10 Version 1909
Microsoft ≫ Windows 10 Version 2004
Microsoft ≫ Windows 7 Version - Update sp1
Microsoft ≫ Windows 8.1 Version -
Microsoft ≫ Windows Rt 8.1 Version -
Microsoft ≫ Windows Server 2012 Version -
Microsoft ≫ Windows Server 2012 Version r2
Microsoft ≫ Windows Server 2016
Microsoft ≫ Windows Server 2019 Version -
Microsoft ≫ Internet Explorer Version 9
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.67% | 0.882 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.6 | 4.9 | 10 |
AV:N/AC:H/Au:N/C:C/I:C/A:C
|
| NIST | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| Microsoft | 4.2 | 1.6 | 2.5 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1567