
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-1380 is a remote code execution vulnerability discovered in Internet Explorer 11's JavaScript engine (jscript9.dll). The vulnerability was disclosed and patched as part of Microsoft's August 2020 Patch Tuesday. It exists in the way that the scripting engine handles objects in memory in Internet Explorer, specifically involving a use-after-free (UAF) bug (CISA Alert, Trend Micro).
The vulnerability is specifically a use-after-free bug in Internet Explorer's JavaScript engine (jscript9.dll) that occurs in the Just-In-Time (JIT) engine. The issue stems from the JIT engine's type inference error during the GlobOpt phase, where it fails to properly handle the side effects of Array.prototype.push operations. This can lead to unsafe direct JavaScript implicit calls in the generated machine code without proper checks, potentially allowing for memory corruption (Trend Micro).
If successfully exploited, this vulnerability could allow an attacker to execute arbitrary code in the context of the current user. If the user has administrative rights, an attacker could take complete control of the affected system, including installing programs, viewing or modifying data, or creating new accounts with full user rights. The vulnerability could be exploited through web-based attack scenarios where a user visits a specially crafted website or through ActiveX controls embedded in applications or Microsoft Office documents (CVE Mitre).
The vulnerability was reported to be under active exploitation at the time of patching. Unlike previous Internet Explorer zero-day attacks that typically targeted vbscript.dll and jscript.dll, this vulnerability specifically targeted the modern JavaScript engine's JIT component in jscript9.dll (Trend Micro).
Microsoft addressed this vulnerability by modifying how the scripting engine handles objects in memory. The fix was released as part of the August 2020 Patch Tuesday updates. Trend Micro Deep Security and Vulnerability Protection users are protected through rule 1010441, while TippingPoint customers are protected by rule 37955 (Trend Micro).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."