Skip to main content

Windows JScript RCE Vulnerability

A vulnerability in Microsoft's Windows operating system could allow a remote user to execute arbitrary code on an affected device.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A vulnerability in Microsoft's Windows operating system could allow a remote user to execute arbitrary code on an affected device.

Threat details

The vulnerability relates to the handling of Error objects in JScript, Microsoft's implementation of the ECMAScript standard. Specially crafted scripts will cause certain pointers to be reused after they have been freed, which an attacker could leverage to execute code in the context of the current process. These scripts can be delivered as downloads on compromised websites or as attachments on email messages.

JScript is compatible with JavaScript, another ECMAScript implementation, although it is unclear if this vulnerability can be exploited using JavaScript.


Remediation steps

Type Step
At the time of publication there is no specific remediation guidance for this vulnerability. Microsoft have stated that that an update is being produced and users are advised to apply this patch as soon as it becomes available.

Last edited: 17 February 2020 12:57 pm