Skip to content
COOEY

EXPOSURES › CVE-2018-8653

CVE-2018-8653

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-8653 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Microsoft Internet Explorer's Scripting Engine suffered a memory corruption vulnerability allowing remote code execution.

A memory corruption flaw in IE's Scripting Engine enabled remote code execution, a critical failure for DIBs relying on legacy browsers or unpatched systems. This unpatched, actively exploited vulnerability (KEV) demonstrates the severe risk of neglecting known CVEs, especially in environments where IE was still in use. DIBs must ensure all legacy software is patched or replaced to prevent similar exposures.

Shame score — Microsoft failed to patch a known, actively exploited memory corruption vulnerability in a widely used product, allowing remote code execution for years.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
Microsoft's handling of the vulnerability was met with criticism, with reports of active exploitation and a slow response to patch the issue.
cooey ↗ severe-fallout -1.00
direct-condemnation
"Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution."
app.opencve.io ↗ severe-fallout -1.00
negative-commentary
"Weaknesses"
www.cvefind.com ↗ severe-fallout -1.00
negative-commentary
"CVE by Categories"
cvedb.shodan.io ↗ severe-fallout -1.00
negative-commentary
"CVE by Products"
github.com ↗ severe-fallout -1.00
negative-commentary
"CVE by CVSS Score"
www.microsoft.com ↗ severe-fallout -1.00
negative-commentary
"CVE Watchtower"
securityonline.info ↗ severe-fallout -1.00
negative-commentary
"CVE Statistics"
AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized