A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767.
Published: 2020-01-20
Zero-day remote code execution vulnerability in Internet Explorer has been observed in attacks. Background On January 17, Microsoft released an out-of-band advisory (ADV200001) for a zero-day remote code execution (RCE) in Internet Explorer that has been exploited in the wild.
https://www.tenable.com/cyber-exposure/2020-threat-landscape-retrospective
https://www.tenable.com/blog/how-covid-19-response-is-expanding-the-cyberattack-surface
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0674
https://github.com/maxpl0it/CVE-2020-0674-Exploit
http://packetstormsecurity.com/files/162565/Microsoft-Internet-Explorer-8-11-Use-After-Free.html
http://packetstormsecurity.com/files/161309/Microsoft-Internet-Explorer-11-Use-After-Free.html
http://packetstormsecurity.com/files/159137/Microsoft-Internet-Explorer-11-Use-After-Free.html