Junglewise Threat Intelligence

CVE-2018-8653: Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

CVE-2018-8653 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

A memory corruption vulnerability exists in the Microsoft Internet Explorer scripting engine due to improper handling of objects in memory. An attacker could exploit this to execute arbitrary code in the context of the current user, typically via a specially crafted website.

Affected products

  • Microsoft Internet Explorer 9
  • Microsoft Internet Explorer 10
  • Microsoft Internet Explorer 11

Timeline

  • 2018-12-19: disclosed: Initial vulnerability disclosure and patch release by Microsoft.
  • 2019-01-03: other: Initial analysis by NIST NVD.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats