CVE-2018-8353

HIGH

Internet Explorer <11 - Memory Corruption

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2018-8353. PoCs published by Google Security Research, whereisr0da.

AI-analyzed exploit summary This is a proof-of-concept exploit for CVE-2018-8353, a use-after-free vulnerability in jscript.dll related to the lastIndex property of a RegExp object. The exploit demonstrates memory corruption in Internet Explorer by triggering garbage collection and reallocating freed memory blocks.

Description

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8355, CVE-2018-8359, CVE-2018-8371, CVE-2018-8372, CVE-2018-8373, CVE-2018-8385, CVE-2018-8389, CVE-2018-8390.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Google Security Research · htmldoswindows
https://www.exploit-db.com/exploits/45279

This is a proof-of-concept exploit for CVE-2018-8353, a use-after-free vulnerability in jscript.dll related to the lastIndex property of a RegExp object. The exploit demonstrates memory corruption in Internet Explorer by triggering garbage collection and reallocating freed memory blocks.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Internet Explorer (jscript.dll)
No auth needed
Prerequisites: Internet Explorer with JScript enabled · Target system must be running a vulnerable version of jscript.dll
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 2 stars
by whereisr0da · poc
https://github.com/whereisr0da/CVE-2018-8353-POC

This repository contains a README referencing a Proof of Concept (PoC) for CVE-2018-8353, a Use After Free vulnerability in the Microsoft Scripting Engine. It points to a Chromium Project Zero issue but does not include actual exploit code.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: Microsoft Scripting Engine (Internet Explorer)
No auth needed
Prerequisites: Target system running vulnerable version of Microsoft Scripting Engine
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/45279/
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1041483
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/105034

Scores

CVSS v3 7.5
EPSS 0.8135
EPSS Percentile 99.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-416
Status published
Products (3)
microsoft/internet_explorer 11
microsoft/internet_explorer 10
microsoft/internet_explorer 9
Published Aug 15, 2018
Tracked Since Feb 18, 2026