Executive brief
A remote code execution vulnerability exists in the Microsoft Scripting Engine due to the way it handles objects in memory within Internet Explorer. An attacker could exploit this memory corruption (specifically an out-of-bounds write) to execute arbitrary code in the context of the current user.
Affected products
- Microsoft Internet Explorer 9
- Microsoft Internet Explorer 10
- Microsoft Internet Explorer 11
Timeline
- 2018-10-11: disclosed: Initial analysis by NIST
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog