CVE-2019-0667 EXPLOIT
7.5
HIGH · CVSS 3.0 · EPSS 31.3% (pctl 98)
Patch early
A public exploit exists.
Description
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0665, CVE-2019-0666, CVE-2019-0772.
Scoring
| CVSS | 7.5 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 31.26% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-787 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-04-08 |
| Last modified | 2026-06-17 |
Affected (9)
| Vendor | Product |
|---|---|
| microsoft | internet explorer |
| microsoft | windows 10 |
| microsoft | windows 7 |
| microsoft | windows 8.1 |
| microsoft | windows rt 8.1 |
| microsoft | windows server 2008 |
| microsoft | windows server 2012 |
| microsoft | windows server 2016 |
| microsoft | windows server 2019 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft VBScript - VbsErase Memory Corruption | 2019-03-19 |
References
→ the Explorer · watch your stack · NVD