CVE-2019-1208
published 2019-09-11CVE-2019-1208: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'…
PriorityP348high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
12.94%
95.9th percentile
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1236.
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer_10 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
| microsoft | internet_explorer_11 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vendor_msrc6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
VBScript Remote Code Execution Vulnerability
vendor_msrc·2019-09-10·CVSS 6.4
CVE-2019-1208 [HIGH] VBScript Remote Code Execution Vulnerability
VBScript Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exp
GHSA
GHSA-v9rw-w6gg-x642: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulner
ghsa_unreviewed·2022-05-24·CVSS 7.5
CVE-2019-1208 [HIGH] GHSA-v9rw-w6gg-x642: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulner
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1236.
GHSA
GHSA-rh9m-8vch-h2gr: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulner
ghsa_unreviewed·2022-05-24·CVSS 7.5
CVE-2019-1236 [HIGH] GHSA-rh9m-8vch-h2gr: A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulner
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1208.
Project0
Project Zero RCA: CVE-2021-26411: Internet Explorer MSHTML Double-Free
project_zero·CVSS 8.8
CVE-2021-26411 [HIGH] Project Zero RCA: CVE-2021-26411: Internet Explorer MSHTML Double-Free
# CVE-2021-26411: Internet Explorer MSHTML Double-Free
*Maddie Stone*
## The Basics
**Disclosure or Patch Date:** 9 March 2021
**Product:** Microsoft Internet Explorer
**Advisory:** https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26411
**Affected Versions:** [KB4601319](https://support.microsoft.com/en-us/topic/february-9-2021-kb4601319-os-builds-19041-804-and-19042-804-87fc8417-4a81-0ebb-5baa-40cfab2fbfde) and previous
**First Patched Version:** [KB5000802](https://support.microsoft.com/en-us/topic/march-9-2021-kb5000802-os-builds-19041-867-and-19042-867-63552d64-fe44-4132-8813-ef56d3626e14)
**Issue/Bug Report:** N/A
**Patch CL:** N/A
**Bug-Introducing CL:** N/A
**Reporter(s):** yangkang(@dnpushme) & huangyi(@C0rk1_H) & Enki
## The Code
**Proof-of-concept:**
``
No detection rules found.
No public exploits indexed.
Checkpoint
16th September – Threat Intelligence Bulletin
blogs_checkpoint·2019-09-16
CVE-2019-1208 16th September – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 16th September – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 16th September 2019, please download our Threat Intelligence Bulletin
Top Attacks and Breaches
Garmin, the GPS technology company, has fallen victim to a data breach after their South African shopping site was hosting a malicious software skimmer, capturing customers’ payment data from the website. The stolen data also included home addresses, phone numbers and email addresses.
Ransomware has hit the Wolc
Trendmicro
BinDiff to Zero-Day: A POC Exploiting CVE-2019-1208
blogs_trendmicro·2019-09-12·CVSS 7.5
CVE-2019-1208 [HIGH] BinDiff to Zero-Day: A POC Exploiting CVE-2019-1208
Exploits & Vulnerabilities
# BinDiff to Zero-Day: A POC Exploiting CVE-2019-1208
This looks furhter into the Internet Explorer vulnerability (CVE-2019-1208), which we discovered through BinDiff (a binary code analysis tool). This is a proof of concept (PoC) showing how it can be fully and consistently exploited in Windows 10 RS5.
By: Elliot Cao
2019/09/12
Read time: ( words)
Save to Folio
Last June, I disclosed a use-after-free (UAF) vulnerability in Internet Explorer (IE) to Microsoft. It was rated as critical, designated as CVE-2019-1208, and then addressed in Microsoft’s September Patch Tuesday. I discovered this flaw through BinDiff (a binary code analysis tool) and wrote a proof of concept (PoC) showing how it can be fully and consistently exploited in Windows 10 RS5.
A more in
Trendmicro
BinDiff to Zero-Day: A POC Exploiting CVE-2019-1208
blogs_trendmicro·2019-09-12·CVSS 7.5
CVE-2019-1208 [HIGH] BinDiff to Zero-Day: A POC Exploiting CVE-2019-1208
Ausnutzung von Schwachstellen
## BinDiff to Zero-Day: A POC Exploiting CVE-2019-1208
This looks furhter into the Internet Explorer vulnerability (CVE-2019-1208), which we discovered through BinDiff (a binary code analysis tool). This is a proof of concept (PoC) showing how it can be fully and consistently exploited in Windows 10 RS5.
By: Elliot Cao Sep 12, 2019 Read time: ( words)
Save to Folio
Last June, I disclosed a use-after-free (UAF) vulnerability in Internet Explorer (IE) to Microsoft. It was rated as critical, designated as CVE-2019-1208 , and then addressed in Microsoft’s September Patch Tuesday . I discovered this flaw through BinDiff (a binary code analysis tool) and wrote a proof of concept (PoC) showing how it can be fully and consistently exploited in Windows 10 RS5.
A
Trendmicro
BinDiff to Zero-Day: A POC Exploiting CVE-2019-1208
blogs_trendmicro·2019-09-12·CVSS 7.5
CVE-2019-1208 [HIGH] BinDiff to Zero-Day: A POC Exploiting CVE-2019-1208
Exploits & Vulnerabilities
## BinDiff to Zero-Day: A POC Exploiting CVE-2019-1208
This looks furhter into the Internet Explorer vulnerability (CVE-2019-1208), which we discovered through BinDiff (a binary code analysis tool). This is a proof of concept (PoC) showing how it can be fully and consistently exploited in Windows 10 RS5.
By: Elliot Cao 2019/09/12 Read time: ( words)
Save to Folio
Last June, I disclosed a use-after-free (UAF) vulnerability in Internet Explorer (IE) to Microsoft. It was rated as critical, designated as CVE-2019-1208 , and then addressed in Microsoft’s September Patch Tuesday . I discovered this flaw through BinDiff (a binary code analysis tool) and wrote a proof of concept (PoC) showing how it can be fully and consistently exploited in Windows 10 RS5.
A more
Trendmicro
BinDiff to Zero-Day: A POC Exploiting CVE-2019-1208
blogs_trendmicro·2019-09-12·CVSS 7.5
CVE-2019-1208 [HIGH] BinDiff to Zero-Day: A POC Exploiting CVE-2019-1208
Exploits & Vulnerabilities
# BinDiff to Zero-Day: A POC Exploiting CVE-2019-1208
This looks furhter into the Internet Explorer vulnerability (CVE-2019-1208), which we discovered through BinDiff (a binary code analysis tool). This is a proof of concept (PoC) showing how it can be fully and consistently exploited in Windows 10 RS5.
By: Elliot Cao
Sep 12, 2019
Read time: ( words)
Save to Folio
Last June, I disclosed a use-after-free (UAF) vulnerability in Internet Explorer (IE) to Microsoft. It was rated as critical, designated as CVE-2019-1208, and then addressed in Microsoft’s September Patch Tuesday. I discovered this flaw through BinDiff (a binary code analysis tool) and wrote a proof of concept (PoC) showing how it can be fully and consistently exploited in Windows 10 RS5.
A more
Trendmicro
BinDiff to Zero-Day: A POC Exploiting CVE-2019-1208
blogs_trendmicro·2019-09-12·CVSS 7.5
CVE-2019-1208 [HIGH] BinDiff to Zero-Day: A POC Exploiting CVE-2019-1208
Exploits & Vulnerabilities
## BinDiff to Zero-Day: A POC Exploiting CVE-2019-1208
This looks furhter into the Internet Explorer vulnerability (CVE-2019-1208), which we discovered through BinDiff (a binary code analysis tool). This is a proof of concept (PoC) showing how it can be fully and consistently exploited in Windows 10 RS5.
By: Elliot Cao Sep 12, 2019 Read time: ( words)
Save to Folio
Last June, I disclosed a use-after-free (UAF) vulnerability in Internet Explorer (IE) to Microsoft. It was rated as critical, designated as CVE-2019-1208 , and then addressed in Microsoft’s September Patch Tuesday . I discovered this flaw through BinDiff (a binary code analysis tool) and wrote a proof of concept (PoC) showing how it can be fully and consistently exploited in Windows 10 RS5.
A mor
Trendmicro
BinDiff to Zero-Day: A POC Exploiting CVE-2019-1208
blogs_trendmicro·2019-09-12·CVSS 7.5
CVE-2019-1208 [HIGH] BinDiff to Zero-Day: A POC Exploiting CVE-2019-1208
Sfruttamento vulnerabilità
## BinDiff to Zero-Day: A POC Exploiting CVE-2019-1208
This looks furhter into the Internet Explorer vulnerability (CVE-2019-1208), which we discovered through BinDiff (a binary code analysis tool). This is a proof of concept (PoC) showing how it can be fully and consistently exploited in Windows 10 RS5.
By: Elliot Cao Sep 12, 2019 Read time: ( words)
Save to Folio
Last June, I disclosed a use-after-free (UAF) vulnerability in Internet Explorer (IE) to Microsoft. It was rated as critical, designated as CVE-2019-1208 , and then addressed in Microsoft’s September Patch Tuesday . I discovered this flaw through BinDiff (a binary code analysis tool) and wrote a proof of concept (PoC) showing how it can be fully and consistently exploited in Windows 10 RS5.
A mor
Trendmicro
BinDiff to Zero-Day: A POC Exploiting CVE-2019-1208
blogs_trendmicro·2019-09-12·CVSS 7.5
CVE-2019-1208 [HIGH] BinDiff to Zero-Day: A POC Exploiting CVE-2019-1208
Exploits y vulnerabilidades
## BinDiff to Zero-Day: A POC Exploiting CVE-2019-1208
This looks furhter into the Internet Explorer vulnerability (CVE-2019-1208), which we discovered through BinDiff (a binary code analysis tool). This is a proof of concept (PoC) showing how it can be fully and consistently exploited in Windows 10 RS5.
By: Elliot Cao Sep 12, 2019 Read time: ( words)
Save to Folio
Last June, I disclosed a use-after-free (UAF) vulnerability in Internet Explorer (IE) to Microsoft. It was rated as critical, designated as CVE-2019-1208 , and then addressed in Microsoft’s September Patch Tuesday . I discovered this flaw through BinDiff (a binary code analysis tool) and wrote a proof of concept (PoC) showing how it can be fully and consistently exploited in Windows 10 RS5.
A mo
Trendmicro
September Patch Tuesday: RDP Vulns and Zero-Days
blogs_trendmicro·2019-09-11·CVSS 8.8
[HIGH] September Patch Tuesday: RDP Vulns and Zero-Days
Exploits & Vulnerabilities
# September Patch Tuesday: RDP Vulns and Zero-Days
Microsoft’s September Patch Tuesday covered a total of 80 CVEs, 17 of which were rated critical.
By: Trend Micro
2019/09/11
Read time: ( words)
Save to Folio
Microsoft’s September Patch Tuesday covered 80 CVEs, 17 of which were rated critical, and included patches for Azure DevOps Server, Chakra Scripting engine, and Microsoft SharePoint. Sixty-two were labeled as important and included patches for Microsoft Excel, Microsoft Edge, and Microsoft Exchange. Only one was rated as moderate.
### Remote desktop vulnerabilities
Continuing the trend from last month, several of the critical patches were for Remote Desktop Clients and are CVE-2019-0787, CVE-2019-0788, CVE-2019-1290, and CVE-2019-1291 — all Remote Co
Trendmicro
September Patch Tuesday: RDP Vulns and Zero-Days
blogs_trendmicro·2019-09-11·CVSS 8.8
[HIGH] September Patch Tuesday: RDP Vulns and Zero-Days
# September Patch Tuesday: RDP Vulns and Zero-Days
Microsoft’s September Patch Tuesday covered a total of 80 CVEs, 17 of which were rated critical.
By: Trend Micro
Sep 11, 2019
Read time: ( words)
Save to Folio
Microsoft’s September Patch Tuesday covered 80 CVEs, 17 of which were rated critical, and included patches for Azure DevOps Server, Chakra Scripting engine, and Microsoft SharePoint. Sixty-two were labeled as important and included patches for Microsoft Excel, Microsoft Edge, and Microsoft Exchange. Only one was rated as moderate.
### Remote desktop vulnerabilities
Continuing the trend from last month, several of the critical patches were for Remote Desktop Clients and are CVE-2019-0787, CVE-2019-0788, CVE-2019-1290, and CVE-2019-1291 — all Remote Code Execution (RCE) vulnera
2019-09-11
Published