ZeroHour

CVE-2019-0676

KEVmass

Information Disclosure in Microsoft Internet Explorer via Improper Memory Handling

CISA: Microsoft Internet Explorer Information Disclosure Vulnerability

CVSS 3.1
6.5 medium
EPSS
8%p94
Published
()
KEV added
AI analysis

CVE-2019-0676 is an information disclosure vulnerability in Microsoft Internet Explorer caused by improper handling of objects in memory. It is exploited remotely via attacker-crafted content, most likely a malicious web page or link, that the victim must open in Internet Explorer, as reflected by the user-interaction requirement in the CVSS vector. A successful attacker can probe the victim's system and test for the presence of specific files on disk, which is useful for reconnaissance and tailoring follow-on attacks; there is no integrity or availability impact. Affected systems are those running Microsoft Internet Explorer, per CISA and Microsoft data. The flaw is listed in the CISA KEV catalog (added 2022-05-23), confirming known exploitation in the wild, with an EPSS 30-day exploitation probability of 7.5% (94th percentile), and remediation is via Microsoft security updates.

What to do: Apply Microsoft security updates for Internet Explorer/Windows per vendor instructions, as required by the CISA KEV listing, and verify patch status across internet-exposed and user workstations. Because exploitation requires user interaction, caution users against opening untrusted links in IE, and consider disabling or removing Internet Explorer where it is no longer needed. Monitor for KEV-driven remediation deadlines and check environments for evidence of the file-existence probing behavior.

Affected
microsoft Internet Explorer
Estimated exposure
masshundreds of millions of Windows devices (Internet Explorer ships bundled with Windows) — Internet Explorer is bundled with Windows across consumer and enterprise fleets, and at the time of disclosure it was the default or built-in browser on a large share of hundreds of millions of Windows PCs, so exposed installations are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka 'Internet Explorer Information Disclosure Vulnerability'.

CISA Known Exploited Vulnerability
Affected
Microsoft Internet Explorer
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
internet explorer
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news