EXPOSURES › CVE-2019-1367
CVE-2019-1367
CRITICAL ⌖ ON CISA KEV · EXPLOITEDA critical, actively exploited memory corruption vulnerability in Microsoft Internet Explorer allowed for remote code execution, highlighting the risks of using unsupported software in DIB environments.
CVE-2019-1367 in Internet Explorer allowed attackers to execute code remotely, exploiting a memory corruption flaw. Given Internet Explorer's end-of-life status and history of vulnerabilities, DIB organizations must immediately eliminate its use to avoid potential data breaches and compliance failures under NIST 800-171. Assess and remediate any systems still using IE.
Shame score — The vulnerability's active exploitation and the product's end-of-life status demonstrate a significant failure in risk management and a lack of proactive security measures.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of the current user.
"CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited."
"Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory."
"Known Exploited Vulnerabilities Catalog | CISA"
"Known Exploited Vulnerabilities Catalog | CISA"
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |