LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-8373: Microsoft Scripting Engine Memory Corruption Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 25, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 15, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-8373 to its Known Exploited Vulnerabilities catalog on Mar 25, 2022, with a federal patch deadline of Apr 15, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer.

CVE-2018-8373 is a remote code execution vulnerability in the Microsoft Internet Explorer scripting engine. It stems from how the engine handles objects in memory, allowing an attacker who can get a user to process malicious content to corrupt memory and potentially run code in the context of the logged-on user. For IT and security teams this matters because Internet Explorer (and its scripting components) may still be present on managed Windows endpoints, embedded in legacy workflows, or reachable via older intranet applications, turning a single drive-by or crafted page into a foothold.

Public detail is limited to the CISA description and the stated weakness; confirm exact impact, affected builds, and exploitation prerequisites against the vendor advisory before prioritizing.

How it works

The flaw is classified as CWE-787 (out-of-bounds write), a memory-corruption class. In the Internet Explorer scripting engine, objects are managed in memory while scripts execute. When the engine mishandles those objects, an attacker-controlled script can cause a write past the intended buffer boundary. Successful corruption can alter control data or function pointers, leading to arbitrary code execution under the privileges of the browser process.

Abuse typically requires the victim to load attacker-supplied web content that exercises the vulnerable scripting path. No further exploit mechanics are provided in the available facts; treat any public proof-of-concept claims cautiously and validate them only against official vendor or trusted researcher write-ups. Because the vulnerability yields remote code execution, it can serve as an initial access vector if unpatched systems remain reachable.

Am I affected? How to find it in your systems

The affected component is the Microsoft Internet Explorer scripting engine. It commonly appears on Windows workstations and servers where Internet Explorer is installed, even if Edge or another browser is the default. Legacy line-of-business apps, ActiveX controls, or Group Policy settings that still invoke IE can keep the engine in the attack surface.

How to remediate

Patch first. Apply the updates Microsoft released for this vulnerability exactly as directed in the vendor advisory. CISA’s required action is to apply updates per vendor instructions; treat that as the primary control.

If you can't patch immediately

When immediate patching is blocked by change windows or compatibility testing, apply compensating controls that shrink the attack surface and improve detection.

These measures reduce risk but do not eliminate it; schedule the official update as soon as possible.

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities can lead to full host compromise and subsequent data theft. The available facts do not document ransomware use of CVE-2018-8373, yet any successful exploitation should be treated as a potential breach. Contain affected hosts, preserve forensic evidence, and follow your incident-response plan. As a quick additional check, users can run a free exposure scan of their email addresses against known breach data sets to see whether credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Internet Explorer Scripting Engine
WeaknessCWE-787
Added to CISA KEVMar 25, 2022
Federal patch deadlineApr 15, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities