cbcvebase.
CVE-2018-8389
published 2018-08-15

CVE-2018-8389: A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory…

PriorityP182high7.5CVSS 3.0
AVNACHPRNUIRSUCHIHAH
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
28.65%
97.9th percentile
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8353, CVE-2018-8355, CVE-2018-8359, CVE-2018-8371, CVE-2018-8372, CVE-2018-8373, CVE-2018-8385, CVE-2018-8390.

Affected

14 ranges
VendorProductVersion rangeFixed in
microsoftchakracore<= 1.10.1
microsoftchakracore
microsoftinternet_explorer
microsoftinternet_explorer
microsoftinternet_explorer
microsoftmicrosoft_edge
microsoftmicrosoft_edge
microsoftmicrosoft_edge
microsoftmicrosoft_edge
microsoftmicrosoft_edge
microsoftmicrosoft_edge
msrcinternet_explorer_10
msrcinternet_explorer_11
msrcinternet_explorer_9

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability exists in the scripting engine's handling of objects in memory within Internet Explorer; monitor for memory corruption patterns triggered via IE scripting engine.
  • Attack vector includes attacker-hosted specially crafted websites delivered through Internet Explorer; monitor for suspicious IE-initiated web traffic and script execution.
  • Attack vector also includes ActiveX controls marked 'safe for initialization' embedded in Office documents hosting the IE rendering engine; monitor for Office processes spawning IE rendering engine (mshtml.dll) with ActiveX instantiation.
  • Compromised or malicious websites serving user-provided content or advertisements are a delivery mechanism; monitor for drive-by download patterns via Internet Explorer.
  • ·Exploit status at time of advisory was 'Publicly Disclosed: No; Exploited: No' but rated 'Exploitation More Likely' for both latest and older software releases — treat as high-priority patching target.
  • ·Affected components are Internet Explorer 9, 10, and 11 via the Microsoft Scripting Engine; scope is limited to IE-based rendering contexts including Office documents using the IE rendering engine.
  • ·CVE-2018-8389 is one of several related Scripting Engine Memory Corruption CVEs patched simultaneously; ensure all sibling CVEs (CVE-2018-8355, CVE-2018-8359, CVE-2018-8371, CVE-2018-8372, CVE-2018-8373, CVE-2018-8385, CVE-2018-8390) are also remediated via the same KB updates.

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
ghsa7.5HIGH
osv7.5HIGH
vulncheck7.5HIGH
vendor_msrc6.4MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.