LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-1367: Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-1367 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of…

CVE-2019-1367 is a memory corruption vulnerability in the scripting engine of Microsoft Internet Explorer. An attacker who successfully exploits it can run code in the security context of the logged-on user. Because the flaw has been tied to ransomware activity, organizations still running Internet Explorer should treat it as a high-priority risk and confirm their exposure against the vendor advisory.

Successful exploitation requires the victim to process malicious content that reaches the scripting engine, typically through browsing or embedded web content. The result is remote code execution under the current user’s privileges, which can lead to further compromise of the endpoint and lateral movement.

How it works

The vulnerability is classified as CWE-787 (out-of-bounds write). The Internet Explorer scripting engine mishandles objects in memory, allowing memory corruption. An attacker can craft content that triggers the flawed handling path; once memory is corrupted, the attacker can redirect execution flow to achieve code execution in the context of the current user.

No special privileges beyond the ability to deliver content to the browser are required for the initial trigger. Specific exploit mechanics, exact trigger conditions, and any version-specific details must be confirmed against the Microsoft advisory; public technical write-ups should be treated as secondary sources only.

Am I affected? How to find it in your systems

Internet Explorer historically shipped with Windows client and server editions and may still be present even when Microsoft Edge is the default browser. Inventory every Windows system for the presence of iexplore.exe and the associated scripting-engine components (jscript.dll and related libraries).

How to remediate

Apply the security updates published by Microsoft for this vulnerability, following the vendor’s installation and reboot guidance. After patching, verify that the update is present via the system’s update history or by querying the relevant file versions.

If you can't patch immediately

Until the vendor update can be deployed, reduce the attack surface and increase detection coverage.

If your data may have been exposed

Actively exploited vulnerabilities of this class have been used to deliver ransomware and other payloads that can lead to data theft or encryption. If you suspect compromise, isolate affected hosts, preserve forensic evidence, and follow your incident-response plan. As an additional check, you can run a free exposure scan of your email addresses against known breach data sets to determine whether credentials or personal information have already appeared in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Internet Explorer
WeaknessCWE-787
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities