CVE-2020-1215

Description

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka VBScript Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2020-1213, CVE-2020-1214, CVE-2020-1216, CVE-2020-1230, CVE-2020-1260.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
7.988

Associated Vulnerability

VulnerabilityOS Platform
Windows OLE Remote Code Execution Vulnerability for Windows 10 Version 1803 for x64-based Systems (KB4561621)Windows
Windows OLE Remote Code Execution Vulnerability for Windows 10 Version 1803 for x86-based Systems (KB4561621)Windows
Windows OLE Remote Code Execution Vulnerability for Windows 10 Version 1809 for x86-based Systems (KB4561608)Windows
Windows OLE Remote Code Execution Vulnerability for Windows Server, version 1903 for x64-based Systems (KB4560960)Windows
Windows OLE Remote Code Execution Vulnerability for Windows 10 Version 1909 for x64-based Systems (KB4560960)Windows
Windows OLE Remote Code Execution Vulnerability for Windows Server, version 1909 for x64-based Systems (KB4560960)Windows
Windows OLE Remote Code Execution Vulnerability for Windows Server 2019 for x64-based Systems (KB4561608)Windows
Windows OLE Remote Code Execution Vulnerability for Windows 10 Version 1809 for x64-based Systems (KB4561608)Windows
Windows OLE Remote Code Execution Vulnerability for Windows 10 Version 1903 for x86-based Systems (KB4560960)Windows
Windows OLE Remote Code Execution Vulnerability for Windows 10 Version 1909 for x86-based Systems (KB4560960)Windows
Windows OLE Remote Code Execution Vulnerability for Windows 10 Version 1903 for x64-based Systems (KB4560960)Windows
Windows OLE Remote Code Execution Vulnerability for Windows 10 Version 1709 for x86-based Systems (KB4561602)Windows
Windows OLE Remote Code Execution Vulnerability for Windows 10 Version 1709 for x64-based Systems (KB4561602)Windows
Windows OLE Remote Code Execution Vulnerability for Windows 10 Version 1507 for x64-based Systems (KB4561649)Windows
Windows OLE Remote Code Execution Vulnerability for Windows Server 2016 for x64-based Systems (KB4561616)Windows
Windows OLE Remote Code Execution Vulnerability for Windows 10 Version 1507 for x86-based Systems (KB4561649)Windows
Windows OLE Remote Code Execution Vulnerability for Windows 10 Version 1607 for x86-based Systems (KB4561616)Windows
Windows OLE Remote Code Execution Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB4561616)Windows
Windows OLE Remote Code Execution Vulnerability for Windows 10 Version 2004 for x64-based Systems (KB4557957)Windows
Windows OLE Remote Code Execution Vulnerability for Windows Server, version 2004 for x64-based Systems (KB4557957)Windows
Windows OLE Remote Code Execution Vulnerability for Windows 10 Version 2004 for x86-based Systems (KB4557957)Windows
2020-06 Cumulative Security Update for Internet Explorer 11 for Windows Server 2008 R2 for x64-based systems (KB4561603)Windows
2020-06 Cumulative Security Update for Internet Explorer 11 for Windows 7 for x64-based systems (KB4561603)Windows
2020-06 Cumulative Security Update for Internet Explorer 9 for Windows Server 2008 for x86-based systems (KB4561603)Windows
VBScript Remote Code Execution Vulnerability for Internet Explorer 11 for Windows Server 2012 R2 for x64-based systems (KB4561603)Windows
Windows OLE Remote Code Execution Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB4561666)Windows
Windows OLE Remote Code Execution Vulnerability for Windows 8.1 for x86-based Systems (KB4561666)Windows
VBScript Remote Code Execution Vulnerability for Internet Explorer 11 for Windows Server 2012 for x64-based systems (KB4561603)Windows
VBScript Remote Code Execution Vulnerability for Internet Explorer 11 for Windows 8.1 for x86-based systems (KB4561603)Windows
2020-06 Cumulative Security Update for Internet Explorer 9 for Windows Server 2008 for x64-based systems (KB4561603)Windows
2020-06 Cumulative Security Update for Internet Explorer 11 for Windows 7 for x86-based systems (KB4561603)Windows
VBScript Remote Code Execution Vulnerability for Internet Explorer 11 for Windows 8.1 for x64-based systems (KB4561603)Windows
Windows OLE Remote Code Execution Vulnerability for Windows 8.1 for x64-based Systems (KB4561666)Windows
2020-06 Security Monthly Quality Rollup for Windows 7 for x64-based Systems (KB4561643)Windows
2020-06 Security Monthly Quality Rollup for Windows 7 for x86-based Systems (KB4561643)Windows
Windows OLE Remote Code Execution Vulnerability for Windows Server 2012 for x64-based Systems (KB4561612)Windows
2020-06 Security Monthly Quality Rollup for Windows Server 2008 R2 for x64-based Systems (KB4561643)Windows
2020-06 Security Monthly Quality Rollup for Windows Server 2008 for x64-based Systems (KB4561670)Windows
2020-06 Security Monthly Quality Rollup for Windows Server 2008 for x86-based Systems (KB4561670)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-290612020-06 Cumulative Update for Windows 10 Version 1803 for x64-based Systems (KB4561621)
PATCH-290622020-06 Cumulative Update for Windows 10 Version 1803 for x86-based Systems (KB4561621)
PATCH-290632020-06 Cumulative Update for Windows 10 Version 1809 for x86-based Systems (KB4561608)
PATCH-290662020-06 Cumulative Update for Windows Server, version 1903 for x64-based Systems (KB4560960)
PATCH-290672020-06 Cumulative Update for Windows 10 Version 1909 for x64-based Systems (KB4560960)
PATCH-290682020-06 Cumulative Update for Windows Server, version 1909 for x64-based Systems (KB4560960)
PATCH-290642020-06 Cumulative Update for Windows Server 2019 for x64-based Systems (KB4561608)
PATCH-290652020-06 Cumulative Update for Windows 10 Version 1809 for x64-based Systems (KB4561608)
PATCH-290692020-06 Cumulative Update for Windows 10 Version 1903 for x86-based Systems (KB4560960)
PATCH-290702020-06 Cumulative Update for Windows 10 Version 1909 for x86-based Systems (KB4560960)
PATCH-290712020-06 Cumulative Update for Windows 10 Version 1903 for x64-based Systems (KB4560960)
PATCH-290722020-06 Cumulative Update for Windows 10 Version 1709 for x86-based Systems (KB4561602)
PATCH-290732020-06 Cumulative Update for Windows 10 Version 1709 for x64-based Systems (KB4561602)
PATCH-290742020-06 Cumulative Update for Windows 10 Version 1507 for x64-based Systems (KB4561649)
PATCH-290762020-06 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4561616)
PATCH-290752020-06 Cumulative Update for Windows 10 Version 1507 for x86-based Systems (KB4561649)
PATCH-290772020-06 Cumulative Update for Windows 10 Version 1607 for x86-based Systems (KB4561616)
PATCH-290782020-06 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB4561616)
PATCH-290792020-06 Cumulative Update for Windows 10 Version 2004 for x64-based Systems (KB4557957)
PATCH-290802020-06 Cumulative Update for Windows Server, version 2004 for x64-based Systems (KB4557957)
PATCH-290812020-06 Cumulative Update for Windows 10 Version 2004 for x86-based Systems (KB4557957)
PATCH-290822020-06 Cumulative Security Update for Internet Explorer 11 for Windows Server 2008 R2 for x64-based systems (KB4561603) (ESU)
PATCH-290832020-06 Cumulative Security Update for Internet Explorer 11 for Windows 7 for x64-based systems (KB4561603) (ESU)
PATCH-290842020-06 Cumulative Security Update for Internet Explorer 9 for Windows Server 2008 for x86-based systems (KB4561603) (ESU)
PATCH-290852020-06 Cumulative Security Update for Internet Explorer 11 for Windows Server 2012 R2 for x64-based systems (KB4561603)
PATCH-290912020-06 Security Monthly Quality Rollup for Windows Server 2012 R2 for x64-based Systems (KB4561666)
PATCH-290922020-06 Security Monthly Quality Rollup for Windows 8.1 for x86-based Systems (KB4561666)
PATCH-290862020-06 Cumulative Security Update for Internet Explorer 11 for Windows Server 2012 for x64-based systems (KB4561603)
PATCH-290872020-06 Cumulative Security Update for Internet Explorer 11 for Windows 8.1 for x86-based systems (KB4561603)
PATCH-290882020-06 Cumulative Security Update for Internet Explorer 9 for Windows Server 2008 for x64-based systems (KB4561603) (ESU)
PATCH-290892020-06 Cumulative Security Update for Internet Explorer 11 for Windows 7 for x86-based systems (KB4561603) (ESU)
PATCH-290902020-06 Cumulative Security Update for Internet Explorer 11 for Windows 8.1 for x64-based systems (KB4561603)
PATCH-290932020-06 Security Monthly Quality Rollup for Windows 8.1 for x64-based Systems (KB4561666)
PATCH-290952020-06 Security Monthly Quality Rollup for Windows 7 for x64-based Systems (KB4561643) (ESU)
PATCH-290962020-06 Security Monthly Quality Rollup for Windows 7 for x86-based Systems (KB4561643) (ESU)
PATCH-290942020-06 Security Monthly Quality Rollup for Windows Server 2012 for x64-based Systems (KB4561612)
PATCH-290972020-06 Security Monthly Quality Rollup for Windows Server 2008 R2 for x64-based Systems (KB4561643) (ESU)
PATCH-291262020-06 Security Monthly Quality Rollup for Windows Server 2008 for x64-based Systems (KB4561670) (ESU)
PATCH-291272020-06 Security Monthly Quality Rollup for Windows Server 2008 for x86-based Systems (KB4561670) (ESU)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234