安全研究

安全漏洞
Microsoft Chakra Scripting Engine内存破坏漏洞(CVE-2020-17131)

发布日期:2020-12-08
更新日期:2020-12-09

受影响系统:
Microsoft Edge (EdgeHTML-based) on Windows Server 2019
Microsoft Edge (EdgeHTML-based) on Windows 10 20H2 for x64-bas
Microsoft Edge (EdgeHTML-based) on Windows 10 20H2 for ARM64-b
Microsoft Edge (EdgeHTML-based) on Windows 10 20H2 for 32-bit
Microsoft Edge (EdgeHTML-based) on Windows 10 2004 for x64-bas
Microsoft Edge (EdgeHTML-based) on Windows 10 2004 for ARM64-b
Microsoft Edge (EdgeHTML-based) on Windows 10 2004 for 32-bit
Microsoft Edge (EdgeHTML-based) on Windows 10 1909 for x64-bas
Microsoft Edge (EdgeHTML-based) on Windows 10 1909 for ARM64-b
Microsoft Edge (EdgeHTML-based) on Windows 10 1909 for 32-bit
Microsoft Edge (EdgeHTML-based) on Windows 10 1903 for x64-bas
Microsoft Edge (EdgeHTML-based) on Windows 10 1903 for ARM64-b
Microsoft Edge (EdgeHTML-based) on Windows 10 1903 for 32-bit
Microsoft Edge (EdgeHTML-based) on Windows 10 1809 for x64-bas
Microsoft Edge (EdgeHTML-based) on Windows 10 1809 for ARM64-b
Microsoft Edge (EdgeHTML-based) on Windows 10 1809 for 32-bit
描述:
CVE(CAN) ID: CVE-2020-17131

Microsoft ChakraCore是使用在Edge浏览器中的一个开源的ChakraJavaScript脚本引擎的核心部分,也可作为单独的JavaScript引擎使用。
Chakra Scripting Engine存在内存破坏漏洞。攻击者可利用该漏洞在目标服务器上执行代码。

<**>

建议:
厂商补丁:

Microsoft
---------
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-17131

浏览次数:5929
严重程度:0(网友投票)
本安全漏洞由绿盟科技翻译整理,版权所有,未经许可,不得转载
绿盟科技给您安全的保障