Microsoft released fixes for CVE-2020-0674, a memory corruption flaw in the Internet Explorer scripting engine that could let an attacker execute arbitrary code in the context of the current user. The company said the vulnerability had been publicly disclosed and exploited in the wild, and warned that systems where users hold administrative privileges could be fully compromised. Microsoft also published mitigations and a workaround that restricts access to JScript.dll, noting that IE11, IE10, and IE9 typically use Jscript9.dll, which is not affected, and that exposure is tied to sites invoking the legacy JScript engine.
Microsoft’s related guidance on Internet Explorer Enhanced Security Configuration (IE ESC) highlights defensive measures for Windows Server environments that reduce exposure to web-based attacks. IE ESC hardens browser security zones, restricts scripting, ActiveX, downloads, and third-party extensions, and reinforces Microsoft’s recommendation to minimize web browsing from servers and tightly control trusted and intranet site assignments. The guidance also warns that incorrectly adding Internet sites to the Local intranet zone can automatically send user credentials, increasing risk during browser-based exploitation attempts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft published CVE-2020-0674, a scripting engine memory corruption vulnerability in Internet Explorer that can lead to remote code execution, and released security updates for affected Internet Explorer versions on supported Windows platforms. Microsoft said the flaw had been publicly disclosed and was being exploited in the wild at the time of publication.
Microsoft published guidance describing Internet Explorer Enhanced Security Configuration on Windows Server, including how it restricts scripting, ActiveX, downloads, and other browser features to reduce exposure to web-based attacks.
Microsoft revised the CVE-2020-0674 advisory to add mitigation and workaround guidance aligned with ADV200001, including that the JScript.dll workaround should be used only when customers could not install the February security updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcetechnet.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.