CVE-2020-1073: Buffer Overflow
Published Jun 9, 2020
·Updated
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'.
Affected Software
12 affected componentsFixes available
nuget/Microsoft.ChakraCore<1.11.20
1.11.20
Microsoft Edge
Microsoft Windows 10
Microsoft Windows 10=1607
Microsoft Windows 10=1709
Microsoft Windows 10=1803
Microsoft Windows 10=1809
Microsoft Windows 10=1903
Microsoft Windows 10=1909
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft ChakraCore<1.11.20
Remediation
Event History
Jun 9, 2020
CVE Published
via MITRE·07:43 PM
Data Sourced
via MITRE·07:43 PM
DescriptionWeakness
May 24, 2022
Advisory Published
05:19 PM
Frequently Asked Questions
1
What is CVE-2020-1073?
CVE-2020-1073 is a remote code execution vulnerability in the ChakraCore scripting engine.
2
How severe is CVE-2020-1073?
CVE-2020-1073 has a severity rating of 8.1, which is considered critical.
3
Which software is affected by CVE-2020-1073?
The affected software includes Microsoft ChakraCore and Microsoft Edge.
4
Is Microsoft Windows 10 vulnerable to CVE-2020-1073?
No, Microsoft Windows 10 is not vulnerable to CVE-2020-1073.
5
How can I fix CVE-2020-1073?
To fix CVE-2020-1073, update Microsoft ChakraCore to version 1.11.20 or higher.