7.6

CVE-2016-0189

Warnung
Exploit
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0187.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Jscript Version 5.8
   Microsoft ≫ Windows Server 2008 Version r2 Update sp1
Microsoft ≫ Vbscript Version 5.7
   Microsoft ≫ Windows Server 2008 Version r2 Update sp1
Microsoft ≫ Vbscript Version 5.8
   Microsoft ≫ Windows Server 2008 Version r2 Update sp1
Microsoft ≫ Vbscript Version 5.7
   Microsoft ≫ Windows Server 2008 Version - Update sp2
   Microsoft ≫ Windows Vista Version - Update sp2
Microsoft ≫ Internet Explorer Version 9
   Microsoft ≫ Windows Server 2008 Version - Update sp2
   Microsoft ≫ Windows Vista Version - Update sp2
Microsoft ≫ Internet Explorer Version 10
   Microsoft ≫ Windows Server 2012 Version -
Microsoft ≫ Internet Explorer Version 11 Update -
   Microsoft ≫ Windows 10 1507 Version -
   Microsoft ≫ Windows 10 1511 Version -
   Microsoft ≫ Windows 7 Version - Update sp1
   Microsoft ≫ Windows 8.1 Version -
   Microsoft ≫ Windows Rt 8.1 Version -
   Microsoft ≫ Windows Server 2008 Version r2 Update sp1 HwPlatform x64
   Microsoft ≫ Windows Server 2012 Version r2

28.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Microsoft Internet Explorer Memory Corruption Vulnerability

Schwachstelle

The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 93.71% 0.998
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 7.6 4.9 10
AV:N/AC:H/Au:N/C:C/I:C/A:C
CISA-ADP 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

http://www.securitytracker.com/id/1035820
Third Party Advisory
Broken Link
VDB Entry
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-051
Patch
Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-053
Patch
Vendor Advisory
http://www.securityfocus.com/bid/90012
Third Party Advisory
Broken Link
VDB Entry
https://www.exploit-db.com/exploits/40118/
Third Party Advisory
VDB Entry
https://www.virusbulletin.com/virusbulletin/2017/01/journey-and-evolution-god-mode-2016-cve-2016-0189/
Third Party Advisory
Exploit
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-0189
US Government Resource