CVE-2020-1037: High severity microsoft edge beta vulnerability
Published May 21, 2020
·Updated
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based), aka 'Chakra Scripting Engine Memory Corruption Vulnerability'.
Affected Software
12 affected componentsFixes available
nuget/Microsoft.ChakraCore<1.11.19
1.11.19
Microsoft Edge
Microsoft Windows 10
Microsoft Windows 10=1607
Microsoft Windows 10=1709
Microsoft Windows 10=1803
Microsoft Windows 10=1809
Microsoft Windows 10=1903
Microsoft Windows 10=1909
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft ChakraCore
Remediation
Event History
May 21, 2020
CVE Published
via MITRE·10:52 PM
Data Sourced
via MITRE·10:52 PM
DescriptionWeakness
May 24, 2022
Advisory Published
05:18 PM
Frequently Asked Questions
1
What is CVE-2020-1037?
CVE-2020-1037 is a remote code execution vulnerability in the Chakra scripting engine in Microsoft Edge.
2
What is the severity of CVE-2020-1037?
CVE-2020-1037 has a high severity rating of 7.
3
How does CVE-2020-1037 affect Microsoft Edge?
CVE-2020-1037 allows remote code execution in the Chakra scripting engine of Microsoft Edge (HTML-based).
4
How can I fix CVE-2020-1037?
To fix CVE-2020-1037, update the Microsoft.ChakraCore package to version 1.11.19.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-1037?
The CWE ID for CVE-2020-1037 is 787.