<p>An attacker could host a specially crafted website that is designed to exploit the vulnerability through Microsoft browsers, and then convince a user to view the website. The attacker could also take advantage of compromised websites, or websites that accept or host user-provided content or advertisements, by adding specially crafted content that could exploit the vulnerability. In all cases, however, an attacker would have no way to force users to view the attacker-controlled content. Instead, an attacker would have to convince users to take action, typically via an enticement in email or instant message, or by getting them to open an email attachment.</p>
<p>The security update addresses the vulnerability by modifying how Microsoft browsers handle objects in memory.</p>
Project Subscriptions
| Vendors | Products |
|---|---|
|
Microsoft
Subscribe
|
Chakracore
Subscribe
Edge
Subscribe
Internet Explorer
Subscribe
Windows 10
Subscribe
Windows 10 1507
Subscribe
Windows 10 1607
Subscribe
Windows 10 1709
Subscribe
Windows 10 1803
Subscribe
Windows 10 1809
Subscribe
Windows 10 1903
Subscribe
Windows 10 1909
Subscribe
Windows 10 2004
Subscribe
Windows 7
Subscribe
Windows 8.1
Subscribe
Windows Rt 8.1
Subscribe
Windows Server 2008
Subscribe
Windows Server 2012
Subscribe
Windows Server 2016
Subscribe
Windows Server 2019
Subscribe
|
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 22 Oct 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 04 Feb 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
kev
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2025-10-21T23:35:36.572Z
Reserved: 2019-11-04T00:00:00.000Z
Link: CVE-2020-0878
Updated: 2024-08-04T06:18:03.385Z
Status : Analyzed
Published: 2020-09-11T17:15:14.370
Modified: 2025-10-29T14:26:50.633
Link: CVE-2020-0878
No data.
OpenCVE Enrichment
No data.