ZeroHour

CVE-2019-1429

KEV PoC mass

Memory corruption RCE in Microsoft Internet Explorer scripting engine

CISA: Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

CVSS 3.1
7.5 high
EPSS
77%p100
Published
()
KEV added
AI analysis

CVE-2019-1429 is a memory corruption flaw (use-after-free/out-of-bounds write, CWE-416/CWE-787) in the way the Internet Explorer scripting engine handles objects in memory, allowing remote code execution. It is triggered remotely by convincing a user to view attacker-controlled web content — for example, a malicious website opened in Internet Explorer or an application embedding the IE engine — requiring no privileges but user interaction (CVSS 3.1 AV:N/AC:H/PR:N/UI:R). A successful exploit runs attacker code with the privileges of the logged-in user, enabling malware installation, data theft, and account compromise. Users of Internet Explorer on Windows are affected, since IE is present by default across Windows installations. The flaw was actively exploited as a zero-day at its November 2019 disclosure (associated with the Magnitude exploit kit per related coverage), carries a public proof-of-concept, and is listed in CISA's Known Exploited Vulnerabilities catalog.

What to do: Apply the November 2019 Microsoft security updates (Internet Explorer cumulative updates) per Microsoft's instructions, as required by the CISA KEV listing. Until patched, avoid browsing untrusted or attacker-influenced websites with Internet Explorer and consider directing users to Microsoft Edge instead of legacy IE. Given active in-the-wild use, prioritize this patch in your deployment schedule and verify IE cumulative updates are installed on all Windows endpoints.

Affected
Microsoft Internet Explorer
Estimated exposure
masshundreds of millions of Windows users (IE ships by default with Windows, and exploit kit delivery puts at least exposed users at broad scale) — Internet Explorer is bundled with every Windows installation, giving a user base in the hundreds of millions even as IE's active browser share declined to roughly 5% around late 2019, and the in-the-wild Magnitude exploit kit delivery…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1426, CVE-2019-1427, CVE-2019-1428.

CISA Known Exploited Vulnerability
Affected
Microsoft Internet Explorer
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
internet explorer
Weakness
CWE-416, CWE-787
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news