CVE-2020-0922: Microsoft COM for Windows Remote Code Execution Vulnerability
<p>A remote code execution vulnerability exists in the way that Microsoft COM for Windows handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system.</p> <p>To exploit the vulnerability, a user would have to open a specially crafted file or lure the target to a website hosting malicious JavaScript.</p> <p>The security update addresses the vulnerability by correcting how Microsoft COM for Windows handles objects in memory.</p>
Other sources
A remote code execution vulnerability exists in the way that Microsoft COM for Windows handles objects in memory, aka 'Microsoft COM for Windows Remote Code Execution Vulnerability'.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-0922?
CVE-2020-0922 is rated as critical due to its potential for remote code execution.
How do I fix CVE-2020-0922?
To fix CVE-2020-0922, apply the latest security updates provided by Microsoft for affected Windows versions.
Which systems are affected by CVE-2020-0922?
CVE-2020-0922 affects various versions of Microsoft Windows including Windows 10, Windows 7, Windows 8.1, and Windows Server editions.
Can CVE-2020-0922 be exploited without user interaction?
Yes, CVE-2020-0922 can potentially be exploited through social engineering, requiring the victim to open a malicious file.
What is the main impact of CVE-2020-0922?
The main impact of CVE-2020-0922 is that an attacker can execute arbitrary code on the target system, compromising its security.