CVE-2018-0987
published 2018-04-12CVE-2018-0987: An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Internet Explorer, aka "Scripting Engine…
PriorityP424medium4.3CVSS 3.0
AVNACLPRNUIRSUCLINAN
EPSS
6.34%
92.9th percentile
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Internet Explorer, aka "Scripting Engine Information Disclosure Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-0981, CVE-2018-0989, CVE-2018-1000.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer_10 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_9 | — | — |
| microsoft | internet_explorer_9 | — | — |
| msrc | internet_explorer_10 | — | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_msrc2.4LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Scripting Engine Information Disclosure Vulnerability
vendor_msrc·2018-04-10·CVSS 2.4
CVE-2018-0987 [MEDIUM] Scripting Engine Information Disclosure Vulnerability
Scripting Engine Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Internet Explorer. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.
In a web-based attack scenario, an attacker could host a website in an attempt to exploit the vulnerability. In addition, compromised websites and websites that accept or host user-provided content could contain specially crafted content that could exploit the vulnerability. However, in all cases an attacker would have no way to force a user to view the attacker-controlled content. Instead, an attacker would have to convince a user to take action. For example, an att
GHSA
GHSA-x5v9-r246-vr73: An information disclosure vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Eng
ghsa_unreviewed·2022-05-13·CVSS 4.3
CVE-2018-0981 [MEDIUM] CWE-787 GHSA-x5v9-r246-vr73: An information disclosure vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Eng
An information disclosure vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Information Disclosure Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-0987, CVE-2018-0989, CVE-2018-1000.
GHSA
GHSA-mh63-77cm-cvj3: An information disclosure vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Eng
ghsa_unreviewed·2022-05-13·CVSS 5.3
CVE-2018-1000 [MEDIUM] CWE-787 GHSA-mh63-77cm-cvj3: An information disclosure vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Eng
An information disclosure vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Information Disclosure Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-0981, CVE-2018-0987, CVE-2018-0989.
GHSA
GHSA-6hmf-7275-3j35: An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Internet Explorer, aka "Scripti
ghsa_unreviewed·2022-05-13·CVSS 5.3
CVE-2018-0987 [MEDIUM] GHSA-6hmf-7275-3j35: An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Internet Explorer, aka "Scripti
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Internet Explorer, aka "Scripting Engine Information Disclosure Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-0981, CVE-2018-0989, CVE-2018-1000.
GHSA
GHSA-c29r-j95m-xvm7: An information disclosure vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Eng
ghsa_unreviewed·2022-05-13·CVSS 5.3
CVE-2018-0989 [MEDIUM] CWE-787 GHSA-c29r-j95m-xvm7: An information disclosure vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Eng
An information disclosure vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Information Disclosure Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-0981, CVE-2018-0987, CVE-2018-1000.
No detection rules found.
No public exploits indexed.
Trendmicro
Microsoft Fixes Vulnerabilities in Fonts and Keyboard
blogs_trendmicro·2018-04-11·CVSS 5.3
[MEDIUM] Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Exploits & Vulnerabilities
## Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Microsof's Patch Tuesday for April addressed security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine.
By: IoT Reputation Service Team 2018/04/11 Read time: ( words)
Save to Folio
Microsoft has rolled out its Patch Tuesday for April to address security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine. Of the 67 listed vulnerabilities, 24 were rated critical. Eight of these were disclosed through Trend Micro’s ZDI program:
CVE-2018-1011
CVE-2018-1008
CVE-2018-1004
CVE-2018-1001
CVE-2018-1000
CVE-2018-0
Trendmicro
Microsoft Fixes Vulnerabilities in Fonts and Keyboard
blogs_trendmicro·2018-04-11·CVSS 5.3
[MEDIUM] Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Exploits & Vulnerabilities
# Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Microsof's Patch Tuesday for April addressed security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine.
By: IoT Reputation Service Team
2018/04/11
Read time: ( words)
Save to Folio
Microsoft has rolled out its Patch Tuesday for April to address security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine. Of the 67 listed vulnerabilities, 24 were rated critical. Eight of these were disclosed through Trend Micro’s ZDI program:
- CVE-2018-1011
- CVE-2018-1008
- CVE-2018-1004
- CVE-2018-1001
- CVE-2018-1000
- CVE
Trendmicro
Microsoft Fixes Vulnerabilities in Fonts and Keyboard
blogs_trendmicro·2018-04-11·CVSS 5.3
[MEDIUM] Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Exploits & Vulnerabilities
## Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Microsof's Patch Tuesday for April addressed security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine.
By: IoT Reputation Service Team Apr 11, 2018 Read time: ( words)
Save to Folio
Microsoft has rolled out its Patch Tuesday for April to address security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine. Of the 67 listed vulnerabilities, 24 were rated critical. Eight of these were disclosed through Trend Micro’s ZDI program:
CVE-2018-1011
CVE-2018-1008
CVE-2018-1004
CVE-2018-1001
CVE-2018-1000
CVE-2018
Trendmicro
Microsoft Fixes Vulnerabilities in Fonts and Keyboard
blogs_trendmicro·2018-04-11·CVSS 5.3
[MEDIUM] Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Ausnutzung von Schwachstellen
## Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Microsof's Patch Tuesday for April addressed security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine.
By: IoT Reputation Service Team Apr 11, 2018 Read time: ( words)
Save to Folio
Microsoft has rolled out its Patch Tuesday for April to address security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine. Of the 67 listed vulnerabilities, 24 were rated critical. Eight of these were disclosed through Trend Micro’s ZDI program:
CVE-2018-1011
CVE-2018-1008
CVE-2018-1004
CVE-2018-1001
CVE-2018-1000
CVE-2
Trendmicro
Microsoft Fixes Vulnerabilities in Fonts and Keyboard
blogs_trendmicro·2018-04-11·CVSS 5.3
[MEDIUM] Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Exploits y vulnerabilidades
## Microsoft Fixes Vulnerabilities in Fonts and Keyboard
Microsof's Patch Tuesday for April addressed security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine.
By: IoT Reputation Service Team Apr 11, 2018 Read time: ( words)
Save to Folio
Microsoft has rolled out its Patch Tuesday for April to address security issues in Internet Explorer (IE), Edge, ChakraCore, Visual Studio, Microsoft Office and Office Services and Web Apps, and Malware Protection Engine. Of the 67 listed vulnerabilities, 24 were rated critical. Eight of these were disclosed through Trend Micro’s ZDI program:
CVE-2018-1011
CVE-2018-1008
CVE-2018-1004
CVE-2018-1001
CVE-2018-1000
CVE-201
Talos
Microsoft Patch Tuesday - April 2018
blogs_talos·2018-04-10·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - April 2018
## Microsoft Patch Tuesday - April 2018
## Microsoft Patch Tuesday - April 2018 Today, Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 65 new vulnerabilities and one advisory, with 25 of them rated critical, 39 of them rated important and one of them rated moderate. These vulnerabilities impact Microsoft Windows, Internet Explorer, Microsoft Edge, Microsoft Office, Windows kernel, Windows Hyper-V, Microsoft Scripting Engine and more.
In addition, an update for Adobe Flash Player was released.
## Critical Vulnerabilities This month, Microsoft is addressing 25 vulnerabilities that are rated "critical".
The vulnerabilities rated as "critical" are listed be
Talos
Microsoft Patch Tuesday - April 2018
blogs_talos·2018-04-10·CVSS 7.5
[HIGH] Microsoft Patch Tuesday - April 2018
## Microsoft Patch Tuesday - April 2018Today, Microsoft has released its monthly set of security advisories for vulnerabilities that have been identified and addressed in various products. This month's advisory release addresses 65 new vulnerabilities and one advisory, with 25 of them rated critical, 39 of them rated important and one of them rated moderate. These vulnerabilities impact Microsoft Windows, Internet Explorer, Microsoft Edge, Microsoft Office, Windows kernel, Windows Hyper-V, Microsoft Scripting Engine and more.
In addition, an update for Adobe Flash Player was released.
### Critical VulnerabilitiesThis month, Microsoft is addressing 25 vulnerabilities that are rated "critical".
The vulnerabilities rated as "critical" are listed below:
CVE-2018-0870 - Internet Explorer Me
http://www.securityfocus.com/bid/103623http://www.securitytracker.com/id/1040653https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0987http://www.securityfocus.com/bid/103623http://www.securitytracker.com/id/1040653https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0987
2018-04-12
Published