CVE-2020-1057
Last modified
CVE-2020-1057 is a medium-severity vulnerability rated 4.2/10 on the CVSS scale. <p>A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. EPSS estimates a 2.06% chance of exploitation in the next 30 days.
Description
<p>A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user.</p> <p>If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.</p> <p>The security update addresses the vulnerability by modifying how the ChakraCore scripting engine handles objects in memory.</p>
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Edge | All versions |
| Microsoft | Chakracore | < 1.11.22 |
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1057Patch, Vendor Advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1057Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-1057?
How severe is CVE-2020-1057?
How do I fix CVE-2020-1057?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-10564An issue was discovered in the File Upload plugin before 4.1…9.8
- CVE-2020-10565grub2-bhyve, as used in FreeBSD bhyve before revision 525916…7.8
- CVE-2020-10566grub2-bhyve, as used in FreeBSD bhyve before revision 525916…7.8
- CVE-2020-10567An issue was discovered in Responsive Filemanager through 9.…9.8
- CVE-2020-10568The sitepress-multilingual-cms (WPML) plugin before 4.3.7-b.…8.8
- CVE-2020-10569SysAid On-Premise 20.1.11, by default, allows the AJP protoc…9.8
- CVE-2020-10570The Telegram application through 5.12 for Android, when Show…6.1
- CVE-2020-10571An issue was discovered in psd-tools before 1.9.4. The Cytho…9.8
- CVE-2020-10573An issue was discovered in Janus through 0.9.1. janus_audiob…7.5
- CVE-2020-10574An issue was discovered in Janus through 0.9.1. janus.c trie…9.8
- CVE-2020-10575An issue was discovered in Janus through 0.9.1. plugins/janu…4.2
- CVE-2020-10576An issue was discovered in Janus through 0.9.1. plugins/janu…5.9
Are you affected by CVE-2020-1057?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
