Security News > 2020 > August > Two 0-Days Under Active Attack, Among 120 Bugs Patched by Microsoft

Two 0-Days Under Active Attack, Among 120 Bugs Patched by Microsoft
2020-08-11 21:12

Two Microsoft vulnerabilities are under active attack, according the software giant's August Patch Tuesday Security Updates.

"[The] vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer," wrote Microsoft.

Todd Schell, senior product manager, security, Ivanti, said a typical attack vector for CVE-2020-1380 is plant malware on a specially crafted website, compromised websites where user-provided content or advertisements are allowed, and through applications or Microsoft Office documents that host the IE rendering engine.

Of the 120 bugs, Microsoft ranked 17 as "Critical" and 103 as "Important" vulnerabilities.

August's bugs bring the number of critical bugs to ten, points out Allan Liska, senior security architect at Recorded Future.


News URL

https://threatpost.com/0-days-active-attack-bugs-patched-microsoft/158280/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2020-08-17 CVE-2020-1380 Out-of-bounds Write vulnerability in Microsoft Internet Explorer 11
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer.
local
low complexity
microsoft CWE-787
7.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 480 75 2308 5127 264 7774