CVE-2020-0848: High severity chakracore vulnerability
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0768, CVE-2020-0823, CVE-2020-0825, CVE-2020-0826, CVE-2020-0827, CVE-2020-0828, CVE-2020-0829, CVE-2020-0830, CVE-2020-0831, CVE-2020-0832, CVE-2020-0833.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-0848?
CVE-2020-0848 is a remote code execution vulnerability in the ChakraCore scripting engine.
What software is affected by CVE-2020-0848?
The affected software includes Microsoft ChakraCore, Microsoft Edge, and certain versions of Microsoft Windows 10 and Windows Server.
What is the severity of CVE-2020-0848?
The severity of CVE-2020-0848 is high, with a CVSS score of 7.5.
How does CVE-2020-0848 work?
CVE-2020-0848 allows remote attackers to execute arbitrary code by exploiting a memory corruption vulnerability in the ChakraCore scripting engine.
Is there a fix available for CVE-2020-0848?
Yes, Microsoft has released patches and updates to address the CVE-2020-0848 vulnerability. It is recommended to install the latest security updates for the affected software.