Skip to content
CVE-2020-0922: Microsoft Windows 10 COM RCE Vulnerability

CVE-2020-0922: Microsoft Windows 10 COM RCE Vulnerability

Sentinelone • March 5, 2026

A remote code execution vulnerability exists in the way that Microsoft COM for Windows handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a user would have to open a specially crafted file or be lured to a website hosting malicious JavaScript.

This vulnerability allows attackers to execute arbitrary code on affected Windows systems through malicious files or websites, potentially leading to complete system compromise.

This vulnerability affects the Microsoft Component Object Model (COM) subsystem in Windows operating systems. COM is a fundamental Windows technology that enables inter-process communication and dynamic object creation. The flaw stems from improper handling of objects in memory by the COM infrastructure, which can be exploited to achieve remote code execution.

The attack requires user interaction—either opening a specially crafted file or visiting a malicious website containing JavaScript designed to trigger the vulnerability. When exploited successfully, an attacker gains the ability to execute arbitrary code with the privileges of the current user. If the user has administrative privileges, the attacker could achieve complete system compromise, including installing programs, modifying data, or creating new accounts with full user rights.

With an EPSS probability of 17.73% (95th percentile), this vulnerability shows elevated likelihood of exploitation compared to typical CVEs, indicating heightened risk in the threat landscape.

The vulnerability originates from improper memory object handling within the Microsoft COM for Windows component. When COM processes certain objects, it fails to properly validate or manage memory operations, creating a condition that attackers can leverage to corrupt memory and redirect execution flow to attacker-controlled code.

The attack is network-based and requires user interaction to succeed. An attacker would need to convince a target user to:

The malicious JavaScript or crafted file would interact with the vulnerable COM component in a way that triggers the improper memory handling, ultimately allowing arbitrary code execution in the context of the current user.

Microsoft has released security updates that address this vulnerability by correcting how Microsoft COM for Windows handles objects in memory. The security update is available through Windows Update and the Microsoft Security Advisory for CVE-2020-0922 .

Organizations should prioritize patching based on the wide range of affected products, spanning Windows 7 through Windows 10 and corresponding server versions. Legacy systems such as Windows 7 and Server 2008 require Extended Security Updates (ESU) subscriptions to receive patches.

Disclaimer : This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Extracted Entities

Attack Types (1)

CVEs (1)

Platforms (1)