CVE-2020-17131: Chakra Scripting Engine Memory Corruption Vulnerability
Published Dec 8, 2020
·Updated
Chakra Scripting Engine Memory Corruption Vulnerability
Affected Software
39 affected componentsFixes available
Microsoft Edge
Microsoft Windows 10=20h2
Microsoft Windows 10=20h2
Microsoft Windows 10=20h2
Microsoft Windows 10=1809
Microsoft Windows 10=1809
Microsoft Windows 10=1809
Microsoft Windows 10=1903
Microsoft Windows 10=1903
Microsoft Windows 10=1903
Microsoft Windows 10=1909
Microsoft Windows 10=1909
Microsoft Windows 10=1909
Microsoft Windows 10=2004
Microsoft Windows 10=2004
Microsoft Windows 10=2004
Microsoft Windows Server 2019
Microsoft ChakraCore<1.11.0
All of the following
Microsoft Edge
Any of the following
Microsoft Windows 10=20h2
Microsoft Windows 10=20h2
Microsoft Windows 10=20h2
Microsoft Windows 10=1809
Microsoft Windows 10=1809
Microsoft Windows 10=1809
Microsoft Windows 10=1903
Microsoft Windows 10=1903
Microsoft Windows 10=1903
Microsoft Windows 10=1909
Microsoft Windows 10=1909
Microsoft Windows 10=1909
Microsoft Windows 10=2004
Microsoft Windows 10=2004
Microsoft Windows 10=2004
Microsoft Windows Server 2019
Microsoft Edge (EdgeHTML-based)
Microsoft Edge (EdgeHTML-based)
Microsoft Edge (EdgeHTML-based)
Microsoft ChakraCore
Remediation
Event History
Dec 8, 2020
CVE Published
via Microsoft·08:00 AM
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
Description
Dec 9, 2020
CVE Published
via MITRE·11:36 PM
Data Sourced
via MITRE·11:36 PM
DescriptionSeverity
Dec 10, 2020
Data Sourced
via NVD·12:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-17131?
CVE-2020-17131 is a memory corruption vulnerability in the Chakra Scripting Engine.
2
Which software is affected by CVE-2020-17131?
Microsoft Edge and Microsoft ChakraCore are affected by CVE-2020-17131.
3
What is the severity of CVE-2020-17131?
CVE-2020-17131 has a severity rating of 7.5 (High).
4
How can I fix CVE-2020-17131?
Apply the necessary security updates provided by Microsoft to address CVE-2020-17131.
5
Where can I find more information about CVE-2020-17131?
You can find more information about CVE-2020-17131 on the Microsoft Security Guidance Advisory page: [link](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-17131)