Advertisement






Microsoft Internet Explorer HTML Objects Uninitialized Memory Corruption Vulnerability

CVE Category Price Severity
CVE-2019-0867 CWE-119 $30,000 High
Author Risk Exploitation Type Date
Google Security Team High Remote 2019-05-02
CPE
cpe:cpe:/a:microsoft:internet_explorer
CVSS EPSS EPSSP
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/S:U/C:H/I:H/A:H 0.09461 0.9094

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2019050019

Below is a copy:

Microsoft Internet Explorer HTML Objects Uninitialized Memory Corruption Vulnerability
A remote code execution vulnerability exists in Internet Explorer due to accesses to uninitialized memory in certain cases of DTML constructs. As 
a result, memory may be corrupted in such a way that an attacker could execute arbitrary code in the context of the logged-on user.

An attacker could exploit the vulnerability by constructing a specially prepared Website, when a user views the Web page, the vulnerability 
could allow remote code execution. An attacker who successfully  exploited this vulnerability could gain the same user rights as the 
logged-on user.

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum