CVE-2020-17054
Description
Chakra Scripting Engine Memory Corruption Vulnerability
Risk Information
Base Score
4.3
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C
EPSS Score
Exploitation Probability
1.658
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Windows Kernel Local Elevation of Privilege Vulnerability for Windows 10 Version 1607 for x86-based Systems (KB4586830) | Windows |
| Windows Kernel Local Elevation of Privilege Vulnerability for Windows Server 2016 for x64-based Systems (KB4586830) | Windows |
| Windows Kernel Local Elevation of Privilege Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB4586830) | Windows |
| Windows Kernel Local Elevation of Privilege Vulnerability for Windows 10 Version 1809 for x86-based Systems (KB4586793) | Windows |
| Windows Kernel Local Elevation of Privilege Vulnerability for Windows 10 Version 1809 for x64-based Systems (KB4586793) | Windows |
| Windows Kernel Local Elevation of Privilege Vulnerability for Windows Server 2019 for x64-based Systems (KB4586793) | Windows |
| Windows Kernel Local Elevation of Privilege Vulnerability for Windows 10 Version 1803 for x86-based Systems (KB4586785) | Windows |
| Windows Kernel Local Elevation of Privilege Vulnerability for Windows 10 Version 1803 for x64-based Systems (KB4586785) | Windows |
| Windows Kernel Local Elevation of Privilege Vulnerability for Windows 10 Version 2004 for x64-based Systems (KB4586781) | Windows |
| Windows Kernel Local Elevation of Privilege Vulnerability for Windows Server, version 2004 for x64-based Systems (KB4586781) | Windows |
| Windows Kernel Local Elevation of Privilege Vulnerability for Windows 10 Version 2004 for x86-based Systems (KB4586781) | Windows |
| Windows Kernel Local Elevation of Privilege Vulnerability for Windows 10 Version 20H2 for x64-based Systems (KB4586781) | Windows |
| Windows Kernel Local Elevation of Privilege Vulnerability for Windows 10 Version 20H2 for x86-based Systems (KB4586781) | Windows |
| Windows Kernel Local Elevation of Privilege Vulnerability for Windows Server, version 1909 for x64-based Systems (KB4586786) | Windows |
| Windows Kernel Local Elevation of Privilege Vulnerability for Windows 10 Version 1903 for x86-based Systems (KB4586786) | Windows |
| Windows Kernel Local Elevation of Privilege Vulnerability for Windows 10 Version 1909 for x64-based Systems (KB4586786) | Windows |
| Windows Kernel Local Elevation of Privilege Vulnerability for Windows Server, version 1903 for x64-based Systems (KB4586786) | Windows |
| Windows Kernel Local Elevation of Privilege Vulnerability for Windows 10 Version 1909 for x86-based Systems (KB4586786) | Windows |
| Windows Kernel Local Elevation of Privilege Vulnerability for Windows 10 Version 1903 for x64-based Systems (KB4586786) | Windows |
| Windows Kernel Local Elevation of Privilege Vulnerability for Windows 10 Version 1507 for x64-based Systems (KB4586787) | Windows |
| Windows Kernel Local Elevation of Privilege Vulnerability for Windows 10 Version 1507 for x86-based Systems (KB4586787) | Windows |
| Vulnerabilities CVE-2020-17048,CVE-2020-17054 are fixed in Nuget - Microsoft.ChakraCore 1.11.23 | Windows |
| Vulnerabilities CVE-2020-17048,CVE-2020-17054 are fixed in Nuget - Microsoft.ChakraCore for Linux 1.11.23 | Linux |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-30254 | 2020-11 Cumulative Update for Windows 10 Version 1607 for x86-based Systems (KB4586830) (CVE-2020-17087) |
| PATCH-30255 | 2020-11 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4586830) (CVE-2020-17087) |
| PATCH-30256 | 2020-11 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB4586830) (CVE-2020-17087) |
| PATCH-30251 | 2020-11 Cumulative Update for Windows 10 Version 1809 for x86-based Systems (KB4586793) (CVE-2020-17087) |
| PATCH-30252 | 2020-11 Cumulative Update for Windows 10 Version 1809 for x64-based Systems (KB4586793) (CVE-2020-17087) |
| PATCH-30253 | 2020-11 Cumulative Update for Windows Server 2019 for x64-based Systems (KB4586793) (CVE-2020-17087) |
| PATCH-30247 | 2020-11 Cumulative Update for Windows 10 Version 1803 for x86-based Systems (KB4586785) (CVE-2020-17087) |
| PATCH-30248 | 2020-11 Cumulative Update for Windows 10 Version 1803 for x64-based Systems (KB4586785) (CVE-2020-17087) |
| PATCH-30241 | 2020-11 Cumulative Update for Windows 10 Version 2004 for x64-based Systems (KB4586781) (CVE-2020-17087) |
| PATCH-30242 | 2020-11 Cumulative Update for Windows Server, version 2004 for x64-based Systems (KB4586781) (CVE-2020-17087) |
| PATCH-30243 | 2020-11 Cumulative Update for Windows 10 Version 2004 for x86-based Systems (KB4586781) (CVE-2020-17087) |
| PATCH-30245 | 2020-11 Cumulative Update for Windows 10 Version 20H2 for x64-based Systems (KB4586781) (CVE-2020-17087) |
| PATCH-30246 | 2020-11 Cumulative Update for Windows 10 Version 20H2 for x86-based Systems (KB4586781) (CVE-2020-17087) |
| PATCH-30235 | 2020-11 Cumulative Update for Windows Server, version 1909 for x64-based Systems (KB4586786) (CVE-2020-17087) |
| PATCH-30236 | 2020-11 Cumulative Update for Windows 10 Version 1903 for x86-based Systems (KB4586786) (CVE-2020-17087) |
| PATCH-30237 | 2020-11 Cumulative Update for Windows 10 Version 1909 for x64-based Systems (KB4586786) (CVE-2020-17087) |
| PATCH-30238 | 2020-11 Cumulative Update for Windows Server, version 1903 for x64-based Systems (KB4586786) (CVE-2020-17087) |
| PATCH-30239 | 2020-11 Cumulative Update for Windows 10 Version 1909 for x86-based Systems (KB4586786) (CVE-2020-17087) |
| PATCH-30240 | 2020-11 Cumulative Update for Windows 10 Version 1903 for x64-based Systems (KB4586786) (CVE-2020-17087) |
| PATCH-30249 | 2020-11 Cumulative Update for Windows 10 Version 1507 for x64-based Systems (KB4586787) (CVE-2020-17087) |
| PATCH-30250 | 2020-11 Cumulative Update for Windows 10 Version 1507 for x86-based Systems (KB4586787) (CVE-2020-17087) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234