CVE-2019-0768 EXPLOIT
4.3
MEDIUM · CVSS 3.0 · EPSS 48.5% (pctl 99)
Patch early
A public exploit exists.
Description
A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restrict VBScript under specific conditions, and to allow requests that should otherwise be ignored, aka 'Internet Explorer Security Feature Bypass Vulnerability'. This CVE ID is unique from CVE-2019-0761.
Scoring
| CVSS | 4.3 (MEDIUM, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N |
| EPSS | 48.5% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-04-09 |
| Last modified | 2026-06-17 |
Affected (3)
| Vendor | Product |
|---|---|
| microsoft | internet explorer |
| microsoft | windows 10 |
| microsoft | windows server 2019 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Internet Explorer 11 - VBScript Execution Policy Bypass in MSHTML | 2019-03-19 |
References
→ the Explorer · watch your stack · NVD