CVE-2018-8653
KEVmassMemory Corruption RCE in Microsoft Internet Explorer Scripting Engine
CISA: Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
CVE-2018-8653 is a memory corruption vulnerability (out-of-bounds write, CWE-787) in how the Microsoft Internet Explorer scripting engine handles objects in memory. An attacker typically triggers it by getting a user to view specially crafted web content in Internet Explorer, causing memory corruption during script object handling. Successful exploitation yields remote code execution with the privileges of the logged-on user, allowing arbitrary code to run on the victim machine. Any system running Microsoft Internet Explorer is affected; because IE ships with Windows and remains in use for legacy enterprise web applications, the plausibly affected population is large, on the order of hundreds of millions of users and devices. The flaw is confirmed exploited in the wild via CISA's KEV catalog (added 2021-11-03, ransomware use unknown), carries a high EPSS score of 29.8% (98th percentile) for exploitation in the next 30 days, and has no known public PoC.
What to do: Apply Microsoft's security updates for Internet Explorer on all Windows systems per vendor instructions, which is CISA's required action for this KEV-listed flaw. Confirm IE cumulative updates are current through Windows Update/WSUS, prioritize endpoints and servers running legacy intranet web applications, and restrict or retire legacy IE-based browsing where feasible while monitoring for follow-on exploitation.
| Microsoft Internet Explorer | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8643.
- Affected
- Microsoft Internet Explorer
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- internet explorer
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H