Skip to content
COOEY

EXPOSURES › CVE-2019-1367

CVE-2019-1367

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-1367 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwarerceexploited-in-wildunpatched

A critical, actively exploited memory corruption vulnerability in Microsoft Internet Explorer allowed for remote code execution, highlighting the risks of using unsupported software in DIB environments.

CVE-2019-1367 in Internet Explorer allowed attackers to execute code remotely, exploiting a memory corruption flaw. Given Internet Explorer's end-of-life status and history of vulnerabilities, DIB organizations must immediately eliminate its use to avoid potential data breaches and compliance failures under NIST 800-171. Assess and remediate any systems still using IE.

Shame score — The vulnerability's active exploitation and the product's end-of-life status demonstrate a significant failure in risk management and a lack of proactive security measures.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of the current user.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
Widespread acknowledgement of a serious vulnerability, with no positive commentary.
cvefeed.io ↗ severe-fallout -0.80
Highlights the severity and real-world exploitation.
"CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited."
cooey ↗ severe-fallout -0.70
Neutral description of the vulnerability.
"Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory."
CISA ↗ severe-fallout -0.50
Standard catalog entry, no commentary.
"Known Exploited Vulnerabilities Catalog | CISA"
CISA ↗ severe-fallout -0.50
Standard catalog entry, no commentary.
"Known Exploited Vulnerabilities Catalog | CISA"
NVD ↗ severe-fallout +0.00
Generic NVD description.
"NVD - Home"
NIST ↗ severe-fallout +0.00
Generic NIST description.
"National Vulnerability Database | NIST"
NVD ↗ severe-fallout +0.00
Generic NVD description.
"NVD - Vulnerabilities"
AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized