CVE-2018-8389
HIGH EXPLOITED IN THE WILD RANSOMWAREInternet Explorer <11 - Memory Corruption
Title source: llmExploitation Summary
CVE-2018-8389 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io), including in ransomware campaigns. EIP tracks 1 public exploit from researchers including sandi-go.
AI-analyzed exploit summary This repository contains a README describing CVE-2018-8389, a use-after-free vulnerability in jscript.dll affecting Internet Explorer. The vulnerability allows remote code execution via memory corruption in the scripting engine.
Description
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. This CVE ID is unique from CVE-2018-8353, CVE-2018-8355, CVE-2018-8359, CVE-2018-8371, CVE-2018-8372, CVE-2018-8373, CVE-2018-8385, CVE-2018-8390.
Exploits (1)
This repository contains a README describing CVE-2018-8389, a use-after-free vulnerability in jscript.dll affecting Internet Explorer. The vulnerability allows remote code execution via memory corruption in the scripting engine.
References (3)
Scores
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H