ZeroHour

CVE-2018-8653

KEVmass

Memory Corruption RCE in Microsoft Internet Explorer Scripting Engine

CISA: Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

CVSS 3.1
7.5 high
EPSS
30%p98
Published
()
KEV added
AI analysis

CVE-2018-8653 is a memory corruption vulnerability (out-of-bounds write, CWE-787) in how the Microsoft Internet Explorer scripting engine handles objects in memory. An attacker typically triggers it by getting a user to view specially crafted web content in Internet Explorer, causing memory corruption during script object handling. Successful exploitation yields remote code execution with the privileges of the logged-on user, allowing arbitrary code to run on the victim machine. Any system running Microsoft Internet Explorer is affected; because IE ships with Windows and remains in use for legacy enterprise web applications, the plausibly affected population is large, on the order of hundreds of millions of users and devices. The flaw is confirmed exploited in the wild via CISA's KEV catalog (added 2021-11-03, ransomware use unknown), carries a high EPSS score of 29.8% (98th percentile) for exploitation in the next 30 days, and has no known public PoC.

What to do: Apply Microsoft's security updates for Internet Explorer on all Windows systems per vendor instructions, which is CISA's required action for this KEV-listed flaw. Confirm IE cumulative updates are current through Windows Update/WSUS, prioritize endpoints and servers running legacy intranet web applications, and restrict or retire legacy IE-based browsing where feasible while monitoring for follow-on exploitation.

Affected
Microsoft Internet Explorer
Estimated exposure
massWell over 1M users — plausibly hundreds of millions of Windows users/devices with Internet Explorer present — Internet Explorer is bundled with Windows client and server editions and retained a double-digit desktop browser market share with a hundreds-of-millions-user install base around the disclosure period, so affected installations are at…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8643.

CISA Known Exploited Vulnerability
Affected
Microsoft Internet Explorer
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
internet explorer
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news