CVE-2020-0970: High severity chakracore vulnerability
Published Apr 15, 2020
·Updated
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0968.
Affected Software
8 affected componentsFixes available
nuget/Microsoft.ChakraCore<1.11.18
1.11.18
Microsoft ChakraCore<1.11.18
Microsoft Edge
Microsoft Windows 10=1803
Microsoft Windows 10=1809
Microsoft Windows 10=1903
Microsoft Windows 10=1909
Microsoft Windows Server 2019
Remediation
Event History
Apr 15, 2020
CVE Published
via MITRE·03:13 PM
Data Sourced
via MITRE·03:13 PM
DescriptionWeakness
May 24, 2022
Advisory Published
05:14 PM
Frequently Asked Questions
1
What is CVE-2020-0970?
CVE-2020-0970 is a remote code execution vulnerability in the ChakraCore scripting engine.
2
How does CVE-2020-0970 occur?
CVE-2020-0970 occurs due to a memory corruption vulnerability in the way ChakraCore handles objects in memory.
3
Which software is affected by CVE-2020-0970?
Microsoft ChakraCore version 1.11.18 and Microsoft Edge are affected by CVE-2020-0970.
4
What is the severity of CVE-2020-0970?
CVE-2020-0970 has a severity rating of 7.5 (High).
5
How can I fix CVE-2020-0970?
To fix CVE-2020-0970, update your Microsoft ChakraCore to version 1.11.18.