Junglewise Threat Intelligence

CVE-2016-0189: Microsoft Internet Explorer Memory Corruption Vulnerability

CVE-2016-0189 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2022-03-28

Technologies: Microsoft Edge, Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

The Microsoft JScript and VBScript engines in Internet Explorer 9 through 11 contain a memory corruption vulnerability. Remote attackers can exploit this via a crafted website to execute arbitrary code or cause a denial of service.

Affected products

  • Microsoft JScript 5.8
  • Microsoft VBScript 5.7
  • Microsoft VBScript 5.8
  • Microsoft Internet Explorer 9
  • Microsoft Internet Explorer 10
  • Microsoft Internet Explorer 11

Timeline

  • 2016-05-10: patched: Microsoft released security bulletins MS16-051 and MS16-053.
  • 2022-03-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-03-28: disclosed: NVD publication date.

Related threats