Junglewise Threat Intelligence

CVE-2019-1367: Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

CVE-2019-1367 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Internet Explorer. Vendors: Microsoft.

Executive brief

A memory corruption vulnerability exists in the Microsoft Internet Explorer scripting engine due to improper handling of objects in memory. Successful exploitation could allow a remote attacker to execute arbitrary code in the context of the current user, typically via a specially crafted website.

Affected products

  • Microsoft Internet Explorer 9, 10, 11

Timeline

  • 2019-09-24: disclosed: Initial analysis by NIST
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: other: Publication date listed in advisory

Related threats