cbcvebase.
CVE-2018-8619
published 2018-12-12

CVE-2018-8619: A remote code execution vulnerability exists when the Internet Explorer VBScript execution policy does not properly restrict VBScript under specific…

PriorityP264high7.5CVSS 3.0
AVNACHPRNUIRSUCHIHAH
EXPLOIT
EPSS
45.76%
98.7th percentile
A remote code execution vulnerability exists when the Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions, aka "Internet Explorer Remote Code Execution Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftinternet_explorer
microsoftinternet_explorer
microsoftinternet_explorer
microsoftinternet_explorer_10
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11

Detection & IOCsextracted from sources · hover to see the quote

registryHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\140C
  • VBScript execution policy bypass via MSXML XSL files — monitor for VBScript execution originating from MSXML/XSL transformation contexts in Internet Explorer, even when the Internet Zone VBScript policy (registry key 140C=3) is enforced.
  • Alert on IE processes spawning child processes or executing arbitrary code at medium-integrity level, which is the privilege level achieved by successful exploitation.
  • Monitor for web-based delivery: users navigating to attacker-controlled sites hosting specially crafted HTML/XSL content designed to trigger VBScript execution through MSXML in IE 9, 10, or 11.
  • Audit the registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\140C; a value of 3 should disable VBScript in the Internet Zone, but this control is bypassed via MSXML XSL — verify patching status rather than relying solely on this policy.
  • ·The VBScript execution policy (registry key 140C=3) intended to disable VBScript in IE 11 for the Internet Zone does NOT cover VBScript embedded in MSXML XSL files, making the policy control insufficient as a standalone mitigation for this CVE.
  • ·This bypass was confirmed on Windows 10 Version 1803 with the latest patches applied at the time of disclosure, meaning fully-patched systems (pre-December 2018 patch) were still vulnerable.

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vendor_msrc6.4MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.