Windows JScript RCE Vulnerability
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
The vulnerability relates to the handling of Error objects in JScript, Microsoft's implementation of the ECMAScript standard. Specially crafted scripts will cause certain pointers to be reused after they have been freed, which an attacker could leverage to execute code in the context of the current process. These scripts can be delivered as downloads on compromised websites or as attachments on email messages.
JScript is compatible with JavaScript, another ECMAScript implementation, although it is unclear if this vulnerability can be exploited using JavaScript.
Remediation steps
Last edited: 17 February 2020 12:57 pm