Junglewise Threat Intelligence

CVE-2019-0676: Microsoft Internet Explorer Information Disclosure Vulnerability

CVE-2019-0676 · Severity: critical · CVSS 6.5 · Exploited in the wild · Published 2022-05-23

Technologies: Microsoft Windows, Microsoft Edge, Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

An information disclosure vulnerability in Microsoft Internet Explorer occurs when the browser improperly handles objects in memory. An attacker can exploit this to test for the presence of specific files on the user's local disk.

Affected products

  • Microsoft Internet Explorer 10, 11
  • Microsoft Windows 7, 8.1, 10, Server 2008, Server 2012, Server 2016, Server 2019

Timeline

  • 2019-02-12: disclosed: Initial release of security advisory by Microsoft.
  • 2019-03-06: other: Initial analysis by NIST NVD.
  • 2022-05-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-05-23: exploited: Confirmed as exploited in the wild.

Related threats