Attacker Value
High
(2 users assessed)
Exploitability
Unknown
(2 users assessed)
User Interaction
Required
Privileges Required
None
Attack Vector
Network
1

Internet Explorer RCE through scripting engine memory corruption (IE 9, 10, 11)

Disclosure Date: November 12, 2019
Exploited in the Wild
Reported by gwillcox-r7
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka ‘Scripting Engine Memory Corruption Vulnerability’. This CVE ID is unique from CVE-2019-1426, CVE-2019-1427, CVE-2019-1428.

Add Assessment

1
Ratings
  • Attacker Value
    High
Technical Analysis

Since this is being exploited in the wild, and affects a wide range of Internet Explorer versions, it looks like it will have some longterm success in targeted phishing and malvertizing campaigns. IE might be down to just 2% of usage, but it’s the only option out of the box on most WIndows Server versions, so it’s at least easy-ish to be running a vulnerable version until you can get patches applied or download a different browser first.

Probably only urgent to patch if you actually use it.

1
Technical Analysis

Reported as exploited in the wild as part of Google’s 2020 0day vulnerability spreadsheet they made available at https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit#gid=1869060786. Original tweet announcing this spreadsheet with the 2020 findings can be found at https://twitter.com/maddiestone/status/1329837665378725888

General Information

Vendors

  • Microsoft

Products

  • Internet Explorer 9,
  • Internet Explorer 11,
  • Internet Explorer 11 on Windows Server 2012,
  • Internet Explorer 11 on Windows 10 Version 1903 for 32-bit Systems,
  • Internet Explorer 11 on Windows 10 Version 1903 for x64-based Systems,
  • Internet Explorer 11 on Windows 10 Version 1903 for ARM64-based Systems,
  • Internet Explorer 10

Additional Info

Technical Analysis