Umbra Wiki cve cve/CVE-2019-1367
Back to wiki

CVE-2019-1367 — Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

provenance: imported · CVE: CVE-2019-1367

CVE-2019-1367: Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Microsoft
Product Internet Explorer
Date added 2021-11-03
Due date 2022-05-03
Ransomware campaign use Known

Description

Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of the current user.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2019-1367

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2019-1367
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog