cbcvebase.
CVE-2019-0676
published 2019-03-05

CVE-2019-0676: An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this…

PriorityP276medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-06-13
Exploited in the wild
EPSS
7.51%
93.8th percentile
An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka 'Internet Explorer Information Disclosure Vulnerability'.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftinternet_explorer
microsoftinternet_explorer
microsoftinternet_explorer_10
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2019-0676 is actively exploited in the wild; attackers deliver exploitation via a malicious website requiring user interaction (browsing to attacker-controlled page)
  • Exploitation of CVE-2019-0676 enables unauthorized file system enumeration — monitor Internet Explorer processes for anomalous file-existence probing activity
  • CVE-2019-0676 was confirmed exploited in the wild at time of patch release (February 2019 Patch Tuesday); treat any unpatched IE instances as actively targeted
  • ·The vulnerability resides in Internet Explorer's memory object handling; the fix changes how IE handles objects in memory — detection should focus on IE process behaviour, not a network-level signature

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vulncheck6.5MEDIUM
cisa6.5MEDIUM
vendor_msrc2.4LOW
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.