CVE-2009-1920

Description

The JScript scripting engine 5.1, 5.6, 5.7, and 5.8 in JScript.dll in Microsoft Windows, as used in Internet Explorer, does not properly load decoded scripts into memory before execution, which allows remote attackers to execute arbitrary code via a crafted web site that triggers memory corruption, aka JScript Remote Code Execution Vulnerability.

Risk Information

Base Score
8.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
50.857

Associated Vulnerability

VulnerabilityOS Platform
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Windows 2000 (KB971961)Windows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.6 for Windows XP (KB971961)Windows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.7 for Windows XP (KB971961)Windows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.8 for Windows XP (KB971961)Windows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.6 for Windows Server 2003 (KB971961)Windows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.7 for Windows Server 2003 (KB971961)Windows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.8 for Windows Server 2003 (KB971961)Windows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.7 for Windows Vista (KB971961) x86 based systemsWindows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.7 for Windows Vista (KB971961) x86 based systems for SP1Windows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.7 for Windows Vista (KB971961) x86 based systems for SP2Windows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.8 for Windows Vista (KB971961) x86 based systemsWindows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.8 for Windows Vista (KB971961) x86 based systems for SP1Windows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.8 for Windows Vista (KB971961) x86 based systems for SP2Windows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.7 for Windows Server 2008 (KB971961) x86 based systemsWindows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.7 for Windows Server 2008 (KB971961) x86 based systems for SP2Windows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.8 for Windows Server 2008 (KB971961) x86 based systemsWindows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.8 for Windows Server 2008 (KB971961) x86 based systems for SP2Windows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.6 for Windows XP x64 Edition (KB971961)Windows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.7 for Windows XP x64 Edition (KB971961)Windows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.8 for Windows XP x64 Edition (KB971961)Windows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.6 for Windows Server 2003 x64 Edition (KB971961)Windows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.7 for Windows Server 2003 x64 Edition (KB971961)Windows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.8 for Windows Server 2003 x64 Edition (KB971961)Windows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.7 for Windows Vista for x64-based Systems (KB971961)Windows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.7 for Windows Vista for x64-based Systems (KB971961) for SP1Windows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.7 for Windows Vista for x64-based Systems (KB971961) for SP2Windows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.8 for Windows Vista for x64-based Systems (KB971961)Windows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.8 for Windows Server 2008 x64 Edition (KB971961)Windows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.7 for Windows Server 2008 x64 Edition (KB971961)Windows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.7 for Windows Server 2008 x64 Edition (KB971961) for SP2Windows
ms09-045: vulnerability in jscript scripting engines could allow remote code execution for Jscript 5.8 for Windows XP (KB971961)Windows
Security Update for Windows 2000 (KB975542)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-7470Security Update for Jscript 5.6 for Windows Server 2003 (KB971961)
PATCH-7471Security Update for Jscript 5.7 for Windows Server 2003 (KB971961)
PATCH-7475Security Update for Jscript 5.7 for Windows Vista (KB971961)
PATCH-7479Security Update for Jscript 5.7 for Windows Server 2008 (KB971961)
PATCH-7480Security Update for Jscript 5.7 for Windows Server 2008 (KB971961)
PATCH-7481Security Update for Jscript 5.8 for Windows Server 2008 (KB971961)
PATCH-7482Security Update for Jscript 5.8 for Windows Server 2008 (KB971961)
PATCH-7485Security Update for Jscript 5.8 for Windows XP x64 Edition (KB971961)
PATCH-7486Security Update for Jscript 5.6 for Windows Server 2003 x64 Edition (KB971961)
PATCH-7487Security Update for Jscript 5.7 for Windows Server 2003 x64 Edition (KB971961)
PATCH-7488Security Update for Jscript 5.8 for Windows Server 2003 x64 Edition (KB971961)
PATCH-7489Security Update for Jscript 5.7 for Windows Vista for x64-based Systems (KB971961)
PATCH-7490Security Update for Jscript 5.7 for Windows Vista for x64-based Systems (KB971961)
PATCH-7491Security Update for Jscript 5.7 for Windows Vista for x64-based Systems (KB971961)
PATCH-7492Security Update for Jscript 5.8 for Windows Vista for x64-based Systems (KB971961)
PATCH-7493Security Update for Jscript 5.8 for Windows Server 2008 x64 Edition (KB971961)
PATCH-7494Security Update for Jscript 5.7 for Windows Server 2008 x64 Edition (KB971961)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234