Back

HIGH

MSHTML Engine Remote Code Execution Vulnerability

Published May 21, 2020

Description

A remote code execution vulnerability exists in the way that the MSHTML engine improperly validates input. An attacker could execute arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. In a HTML editing attack scenario, an attacker could trick a user into editing a specially crafted file that is designed to exploit the vulnerability. The security update addresses the vulnerability by modifying how MSHTML engine validates input.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (0)

No CWE recorded.

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner microsoft
Published May 21, 2020
Updated Aug 19, 2026
Reserved Nov 4, 2019

CISA Vulnrichment

No data

NVD

Status Modified
Modified Aug 19, 2026

Red Hat

No data

ENISA EUVD

Assigner microsoft
Published May 21, 2020
Updated Aug 19, 2026

GitHub

No data