Permissions, Privileges, and Access Controls in Microsoft Internet Explorer - CVE-2019-0768

 

Permissions, Privileges, and Access Controls in Microsoft Internet Explorer - CVE-2019-0768

Published: March 13, 2019 / Updated: June 17, 2021


Vulnerability identifier: #VU17953
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-0768
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to incorrect implementation of the Internet Explorer VBScript execution policy. A remote attacker can create a specially crafted web page, trick the victim into visiting it and trigger the VBScript engine to send requests that should otherwise be ignored.


Affected software

Microsoft Internet Explorer

How to mitigate CVE-2019-0768

Install updates from vendor's website.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins