cbcvebase.
CVE-2019-0666
published 2019-04-08

CVE-2019-0666: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution…

PriorityP275high7.5CVSS 3.0
AVNACHPRNUIRSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
20.40%
97.2th percentile
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0665, CVE-2019-0667, CVE-2019-0772.

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftinternet_explorer
microsoftinternet_explorer
microsoftinternet_explorer
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_server
microsoftwindows_server

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability exists in the VBScript engine's handling of objects in memory via Internet Explorer; monitor for suspicious IE-rendered VBScript execution that may corrupt memory and lead to arbitrary code execution
  • Watch for ActiveX controls marked 'safe for initialization' embedded in Office documents or applications hosting the IE rendering engine as a delivery vector for exploitation
  • ·Exploit status is rated 'Exploitation More Likely' for both latest and older software releases, but no public exploit or active in-the-wild exploitation was confirmed at time of advisory publication
  • ·CVE-2019-0666 is a distinct vulnerability from the related VBScript engine RCE CVEs CVE-2019-0665, CVE-2019-0667, and CVE-2019-0772; detections should not be conflated across these CVEs

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vulncheck7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat6.1MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.