EXPOSURES › CVE-2018-8653
CVE-2018-8653
HIGH ⌖ ON CISA KEV · EXPLOITEDMicrosoft Internet Explorer's Scripting Engine suffered a memory corruption vulnerability allowing remote code execution.
A memory corruption flaw in IE's Scripting Engine enabled remote code execution, a critical failure for DIBs relying on legacy browsers or unpatched systems. This unpatched, actively exploited vulnerability (KEV) demonstrates the severe risk of neglecting known CVEs, especially in environments where IE was still in use. DIBs must ensure all legacy software is patched or replaced to prevent similar exposures.
Shame score — Microsoft failed to patch a known, actively exploited memory corruption vulnerability in a widely used product, allowing remote code execution for years.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution.
"Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution."
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |