← לוח פגיעויות

CVE-2016-0189

גבוהה 7.5 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Microsoft Internet Explorer Memory Corruption Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0187.

מדדים

CVSS 3.1
7.5 (HIGH) מקור הציון: NVD CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
93% (אחוזון 100) נכון ל-24/7/2026
CWE
CWE-787

מוצרים מושפעים

microsoft: jscript; microsoft: vbscript; microsoft: windows server 2008; microsoft: windows vista; microsoft: internet explorer; microsoft: windows server 2012; microsoft: windows 10 1507; microsoft: windows 10 1511; microsoft: windows 7; microsoft: windows 8.1; microsoft: windows rt 8.1

קישורים