ZeroHour

CVE-2019-1367

KEV ransomwaremass

Memory Corruption RCE in Microsoft Internet Explorer Scripting Engine

CISA: Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

CVSS 3.1
7.5 high
EPSS
52%p99
Published
()
KEV added
AI analysis

CVE-2019-1367 is a memory corruption flaw (CWE-787, out-of-bounds write) in the way the Internet Explorer scripting engine handles objects in memory, enabling remote code execution when the corrupted objects are processed. Attackers trigger it by convincing a user to load malicious web content in an affected Internet Explorer installation — such as visiting an attacker-controlled or compromised page, or opening a document/application that hosts IE — with user interaction required per the CVSS vector. Successful exploitation executes attacker code with the user's privileges; the flaw was exploited as an actively-attacked zero-day, with distribution observed through the Magnitude exploit kit, prompting Microsoft to release an out-of-band emergency fix. Any Windows system with an affected Internet Explorer installation is exposed, with enterprise users dependent on IE for legacy web applications at particular risk. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03, with known ransomware use), EPSS estimates a 52.4% probability of exploitation within 30 days, and no public proof-of-concept is catalogued.

What to do: Apply Microsoft's out-of-band (September 2019) and subsequent cumulative Windows/Internet Explorer security updates on all endpoints, per the vendor's instructions, since this is a KEV-listed flaw with known ransomware use; Microsoft's documented mitigation, restricting access to the IE scripting engine component (jscript.dll) and reducing use of Internet Explorer in favor of a modern browser, can protect systems until patched. Verify the update applied cleanly — users reportedly experienced problems with the initial patches — and prioritize user workstations and any systems used to browse untrusted content.

Affected
Microsoft Internet Explorer
Estimated exposure
masstens of millions to hundreds of millions of Windows endpoints with Internet Explorer present (IE is bundled with Windows) — Internet Explorer is included with Windows, whose installed base ran to hundreds of millions of devices at the time of disclosure, and heavy enterprise reliance on IE for legacy web apps kept large endpoint populations exposed; exact…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1221.

CISA Known Exploited Vulnerability
Affected
Microsoft Internet Explorer
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
internet explorer
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news