Synced 17 Sept 2026 15:07 UTC Account
← All products

CVE-2020-1064

HIGH severity · CVSS 7.5
7.5CVSS HIGH

Summary

A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input.An attacker could execute arbitrary code in the context of the current user, aka 'MSHTML Engine Remote Code Execution Vulnerability'.

Impact & exploitability

Attack vectorNetwork
Attack complexityHigh
Privileges requiredNone
User interactionRequired
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
Exploit probability (EPSS)7%

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Recommendation

Apply the vendor fix promptly. Open any affected product above for its exact safe version.

Official patch: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1064 ↗