7.5

CVE-2020-17131

Chakra Scripting Engine Memory Corruption Vulnerability

Data is provided by the National Vulnerability Database (NVD)
MicrosoftEdge Version-
   MicrosoftWindows 10 Version20h2 HwPlatformarm64
   MicrosoftWindows 10 Version20h2 HwPlatformx64
   MicrosoftWindows 10 Version20h2 HwPlatformx86
   MicrosoftWindows 10 Version1809 HwPlatformarm64
   MicrosoftWindows 10 Version1809 HwPlatformx64
   MicrosoftWindows 10 Version1809 HwPlatformx86
   MicrosoftWindows 10 Version1903 HwPlatformarm64
   MicrosoftWindows 10 Version1903 HwPlatformx64
   MicrosoftWindows 10 Version1903 HwPlatformx86
   MicrosoftWindows 10 Version1909 HwPlatformarm64
   MicrosoftWindows 10 Version1909 HwPlatformx64
   MicrosoftWindows 10 Version1909 HwPlatformx86
   MicrosoftWindows 10 Version2004 HwPlatformarm64
   MicrosoftWindows 10 Version2004 HwPlatformx64
   MicrosoftWindows 10 Version2004 HwPlatformx86
   MicrosoftWindows Server 2019 Version-
MicrosoftChakracore Version < 1.11.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.43% 0.799
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
nvd@nist.gov 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
secure@microsoft.com 4.2 1.6 2.5
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.