cbcvebase.
CVE-2016-0189
published 2016-05-11

CVE-2016-0189: The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to…

PriorityP190high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-04-18
Exploited in the wild
EPSS
93.16%
99.8th percentile
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0187.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftinternet_explorer
microsoftinternet_explorer
microsoftinternet_explorer
microsoftjscript
microsoftvbscript
microsoftvbscript
msrcinternet_explorer_10
msrcinternet_explorer_10_on_windows_server_2012
msrcinternet_explorer_11
msrcinternet_explorer_11_on_windows_10_for_32-bit_systems
msrcinternet_explorer_11_on_windows_10_for_x64-based_systems
msrcinternet_explorer_11_on_windows_10_version_1511_for_32-bit_systems
msrcinternet_explorer_11_on_windows_10_version_1511_for_x64-based_systems
msrcinternet_explorer_11_on_windows_7_for_32-bit_systems_service_pack_1
msrcinternet_explorer_11_on_windows_7_for_x64-based_systems_service_pack_1
msrcinternet_explorer_11_on_windows_8.1_for_32-bit_systems
msrcinternet_explorer_11_on_windows_8.1_for_x64-based_systems
msrcinternet_explorer_11_on_windows_rt_8.1
msrcinternet_explorer_11_on_windows_server_2008_r2_for_x64-based_systems_service_pac
msrcinternet_explorer_11_on_windows_server_2012_r2
msrcinternet_explorer_9
msrcinternet_explorer_9_on_windows_server_2008_for_32-bit_systems_service_pack_2
msrcinternet_explorer_9_on_windows_server_2008_for_x64-based_systems_service_pack_2
msrcinternet_explorer_9_on_windows_vista_service_pack_2
msrcinternet_explorer_9_on_windows_vista_x64_edition_service_pack_2

Detection & IOCsextracted from sources · hover to see the quote

hash6ea344d0db80ab6e5cabdc9dcecd5ad4
hashb23745bcd2937b9cfaf6a60ca72d3d67
  • CVE-2016-0189 exploit technique involves modifying the SafeMode flag in the VBScript Engine to obtain execution permission from Shell.Application and run shellcode
  • Terror EK uses cookie detection to prevent repeated exploit site visits; monitor for exploit kit cookie-based fingerprinting behavior
  • CVE-2016-0189 was rapidly adopted by Sundown EK in July 2016; monitor for Sundown EK traffic patterns targeting IE users
  • Smoke Loader downloader Trojan is the malware payload delivered via Terror EK campaigns exploiting CVE-2016-0189
  • Terror EK SWF payloads are protected with 'DComSoft SWF protector' to evade decompiler-based detection
  • For Vista and Windows Server 2008, CVE-2016-0189 is patched separately via MS16-053 (JScript/VBScript package), not just MS16-051 (IE); ensure both patches are applied
  • ·CVE-2016-0189 affects JScript 5.8 and VBScript 5.7/5.8 as used in Internet Explorer 9 through 11; patched by MS16-051 (IE) and MS16-053 (standalone JScript/VBScript for Vista/Server 2008)
  • ·CVE-2016-0189 exploit does not work on systems with updated Internet Explorer versions; patching IE is the primary mitigation

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vulncheck7.5HIGH
cisa7.5HIGH
vendor_msrc7.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.