Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2019-0768Improper Input Validation in Microsoft Internet Explorer 11

Severity
4.3MEDIUMNVD
CNA6.5
EPSS
72.4%
top 1.24%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedApr 9
Latest updateMay 13

Description

A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions, and to allow requests that should otherwise be ignored, aka 'Internet Explorer Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0761.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-x6pv-8jh5-cv2g: A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restrict VBScript under specific con2022-05-13
CVEList
CVE-2019-0768: A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restrict VBScript under specific con2019-04-09

💥Exploits & PoCs

1
Exploit-DB
Microsoft Internet Explorer 11 - VBScript Execution Policy Bypass in MSHTML2019-03-19

📋Vendor Advisories

1
Microsoft
Internet Explorer Security Feature Bypass Vulnerability2019-03-12
CVE-2019-0768 — Improper Input Validation in Microsoft | cvebase