"MS.IE.VBScript.Engine.SafeArrayLock.Use.After.Free"
                
                    - 特征库ID:
                        
48975
 
                    - 漏洞级别:
                        
high
 
                    - CVE ID:
                        
CVE-2020-1035
 
                    - 建议的动作:
                        
drop
 
                    - 受影响的系统:
                        
Windows
 
                    - 协议:
                        
tcp
 
                
             
            
                攻击漏洞描述
                这表明企图利用 Microsoft Internet Explorer VBScript 引擎中的 Use After Free 漏洞进行攻击。该漏洞是由于处理恶意制作的网页时易受攻击的应用程序中的错误造成的。攻击者可以通过诱使毫无戒心的用户访问恶意网页并在应用程序的上下文中执行任意代码来利用这一点。
             
            
                影响范围
                Internet Explorer 9 on Windows Server 2008 for 32-bit Systems Service Pack 2 
Internet Explorer 9 on Windows Server 2008 for x64-based Systems Service Pack 2 
Internet Explorer 11 on Windows 10 Version 1803 for 32-bit Systems 
Internet Explorer 11 on Windows 10 Version 1803 for x64-based Systems 
Internet Explorer 11 on Windows 10 Version 1803 for ARM64-based Systems 
Internet Explorer 11 on Windows 10 Version 1809 for 32-bit Systems 
Internet Explorer 11 on Windows 10 Version 1809 for x64-based Systems 
Internet Explorer 11 on Windows 10 Version 1809 for ARM64-based Systems 
Internet Explorer 11 on Windows Server 2019 
Internet Explorer 11 on Windows 10 Version 1909 for 32-bit Systems 
Internet Explorer 11 on Windows 10 Version 1909 for x64-based Systems 
Internet Explorer 11 on Windows 10 Version 1909 for ARM64-based Systems 
Internet Explorer 11 on Windows 10 Version 1709 for 32-bit Systems 
Internet Explorer 11 on Windows 10 Version 1709 for x64-based Systems 
Internet Explorer 11 on Windows 10 Version 1709 for ARM64-based Systems 
Internet Explorer 11 on Windows 10 Version 1903 for 32-bit Systems 
Internet Explorer 11 on Windows 10 Version 1903 for x64-based Systems 
Internet Explorer 11 on Windows 10 Version 1903 for ARM64-based Systems 
Internet Explorer 11 on Windows 10 for 32-bit Systems 
Internet Explorer 11 on Windows 10 for x64-based Systems 
Internet Explorer 11 on Windows 10 Version 1607 for 32-bit Systems 
Internet Explorer 11 on Windows 10 Version 1607 for x64-based Systems 
Internet Explorer 11 on Windows Server 2016 
Internet Explorer 11 on Windows 7 for 32-bit Systems Service Pack 1 
Internet Explorer 11 on Windows 7 for x64-based Systems Service Pack 1 
Internet Explorer 11 on Windows 8.1 for 32-bit systems 
Internet Explorer 11 on Windows 8.1 for x64-based systems 
Internet Explorer 11 on Windows RT 8.1 
Internet Explorer 11 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 
Internet Explorer 11 on Windows Server 2012 
Internet Explorer 11 on Windows Server 2012 R2
             
            
                可能带来的后果
                系统被入侵:远程攻击者可以控制易受攻击的系统。
             
            
                解决办法
                应用供应商提供的最新升级或补丁。 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1035