cbcvebase.
CVE-2019-0940
published 2019-05-16

CVE-2019-0940: A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption…

PriorityP351high7.5CVSS 3.0
AVNACHPRNUIRSUCHIHAH
EPSS
23.10%
97.5th percentile
A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'.

Affected

54 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftinternet_explorer
microsoftinternet_explorer
microsoftinternet_explorer_10
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11
microsoftinternet_explorer_11

Detection & IOCsextracted from sources · hover to see the quote

  • Exploitation vector is a specially crafted website delivered via Microsoft browsers (IE/Edge); monitor for drive-by browsing activity where users are directed to attacker-controlled or compromised web pages exploiting browser memory corruption
  • Also monitor for exploitation via compromised legitimate websites or sites hosting user-provided content/advertisements containing malicious content targeting Microsoft browsers
  • Initial delivery commonly via phishing email or instant message lures directing users to open attachments or visit malicious URLs; correlate browser process anomalies with recent email/IM activity
  • Successful exploitation results in code execution under the current user context; if the user has admin rights, full system takeover is possible — monitor for unexpected child processes spawned by Microsoft browser processes (iexplore.exe, MicrosoftEdge.exe) and privilege-sensitive actions such as account creation or software installation
  • ·Exploitation likelihood is rated 'More Likely' for both latest and older software releases, increasing urgency of patching unpatched Microsoft browser deployments
  • ·No public exploit or in-the-wild exploitation confirmed at time of advisory; however, the 'More Likely' rating warrants proactive detection posture
  • ·The vulnerability is rooted in how Microsoft browsers handle objects in memory; detection based solely on network traffic will be insufficient — host-based behavioral monitoring of browser processes is required

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vendor_msrc4.2MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.