cbcvebase.
CVE-2018-0955
published 2018-05-09

CVE-2018-0955: A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory…

PriorityP275high7.5CVSS 3.0
AVNACHPRNUIRSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
14.44%
96.2th percentile
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-0945, CVE-2018-0946, CVE-2018-0951, CVE-2018-0953, CVE-2018-0954, CVE-2018-1022, CVE-2018-8114, CVE-2018-8122, CVE-2018-8128, CVE-2018-8137, CVE-2018-8139.

Affected

10 ranges
VendorProductVersion rangeFixed in
microsoftchakracore<= 1.8.3
microsoftchakracore
microsoftinternet_explorer
microsoftinternet_explorer
microsoftinternet_explorer
microsoftmicrosoft_edge
microsoftmicrosoft_edge
msrcinternet_explorer_10
msrcinternet_explorer_11
msrcinternet_explorer_9

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability exists in the scripting engine's handling of objects in memory within Internet Explorer; monitor for memory corruption patterns triggered via IE rendering engine (including embedded ActiveX controls in Office documents or applications hosting the IE rendering engine)
  • Watch for web-based delivery via specially crafted websites targeting Internet Explorer users, as well as ActiveX controls marked 'safe for initialization' embedded in Office documents or applications hosting the IE rendering engine
  • Monitor for exploitation attempts via compromised websites or sites hosting user-provided content/advertisements delivering specially crafted content through Internet Explorer
  • ·Exploit Status is rated 'Exploitation More Likely' for both latest and older software releases, but as of the advisory there is no public exploit or confirmed in-the-wild exploitation
  • ·The NVD source (DOC 1) describes CVE-2018-0954, not CVE-2018-0955; the two are distinct CVEs affecting overlapping Microsoft browser/scripting engine components — do not conflate indicators across them

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
ghsa7.5HIGH
osv7.5HIGH
vulncheck7.5HIGH
vendor_msrc6.4MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.