Junglewise Threat Intelligence

CVE-2019-0752: Microsoft Internet Explorer Type Confusion Vulnerability

CVE-2019-0752 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2022-02-15

Technologies: Microsoft Edge, Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

A type confusion vulnerability (CWE-843) in the Microsoft Internet Explorer scripting engine allows for remote code execution. The flaw occurs due to the way the engine handles objects in memory, potentially leading to memory corruption.

Affected products

  • Microsoft Internet Explorer 11 11

Timeline

  • 2019-04-09: advisory: MSRC advisory published
  • 2022-02-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-02-15: disclosed: NVD publication date

Related threats