CVE-2020-0674
ENISA EUVD: EUVD-2020-2167 ↗
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 3, 2026
8 articles
EPSS Score
Source: FIRST.org · 2026-05-24
93.78%
probability
This CVE has a 93.78% probability
of being exploited in the next 30 days.
0%
Top 99.9th percentile of all CVEs
100%
CVSS v3.1
Source: NVD7.5
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Description
Project ZeroUnspecified memory corruption in Internet Explorer
Affected Products
Attack Intelligence
CWE-118
· Incorrect Access of Indexable Resource ('Range Error')
CWE-119
· Buffer Overflow
CWE-416
· Use After Free
CWE-664
· Improper Control of a Resource Through its Lifetime
CWE-666
· Operation on Resource in Wrong Phase of Lifetime
CWE-672
· Operation on a Resource after Expiration or Release
CWE-825
· Expired Pointer Dereference
Google Project Zero
Patched
Feb. 11, 2020
Reported by
Yi Huang(@C0rk1_H) & Kang Yang(@dnpushme) of Qihoo 360 ATA, Clément Lecigne of Google’s Threat Analysis Group
Root Cause Analysis
https://googleprojectzero.github.io/0days-in-the-wild//0day-RCAs/2020/CVE-2020-0674.html
Exploits & PoC
Neko-chanQwQ/CVE-2020-0674-PoC
随便放点自己弄的小东西
1
1 repo — triés par ⭐
Rechercher sur GitHub ↗
Microsoft's February 2020 Patch Tuesday Fixes 99 Flaws, IE 0day
BleepingComputer
Feb 11, 2020
Microsoft Patches Actively Exploited Internet Explorer Zero-Day
BleepingComputer
Feb 11, 2020
Actively Exploited IE 11 Zero-Day Bug Gets Temporary Patch
BleepingComputer
Jan 21, 2020
Microsoft Issues Mitigation for Actively Exploited IE Zero-Day
BleepingComputer
Jan 17, 2020
Microsoft's IE Zero-day Fix is Breaking Windows Printing
BleepingComputer
Jan 26, 2020
February 2020 Patch Tuesday – 99 Vulns, 12 Critical, Patch for IE 0-Day, Exchange Vuln, Adobe Vulns
Qualys
Feb 11, 2020
Security Advisory 2020-006
CERT-EU
Jan 20, 2020
Signal Intelligence
Confidence
85%
EPSS
93.78%
CVSS v3.1
7.5
Mentions
8
Last Seen
Feb 11, 2020
CNA Information
Analyst Note
CVE-2020-0674 is confirmed as a memory corruption vulnerability in Internet Explorer's scripting engine with high CVSS severity (7.5). The vulnerability is documented by CERT-EU and was tracked by Google Project Zero, providing credible independent verification despite limited public articles. The detailed differentiation from related CVEs strengthens the legitimacy of this distinct vulnerability report.
Threat Actors 2
FusionCore
apt_group
🇪🇺 EU
DNSpionage
apt_group
Information theft and espionage
🇮🇷 IR
Triage Info
Decided atMar 03, 2026