EXPOSURES › CVE-2019-0752
CVE-2019-0752
CRITICAL ⌖ ON CISA KEV · EXPLOITEDMicrosoft Internet Explorer's type confusion vulnerability allowed remote code execution and was actively exploited, highlighting the risks of using unsupported software in DIB environments.
A type confusion vulnerability in Internet Explorer enabled remote code execution, which was actively exploited in ransomware attacks. DIB organizations still using Internet Explorer face significant compliance risks under CMMC and NIST 800-171, requiring immediate remediation – ideally, complete removal. Failure to address this exposes systems to compromise and potential data breaches.
Shame score — The vulnerability's exploitation in ransomware attacks, combined with Internet Explorer's end-of-life status and known history of security issues, demonstrates a significant failure in security management and risk mitigation.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |