CVE-2019-0676
medium · 6.5Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2022-05-23Remediation due 2022-06-13
An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka 'Internet Explorer Information Disclosure Vulnerability'.
6.5
CVSS
7.5%
EPSS (exploit prob.)
94th
EPSS percentile
2019-03-05
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | internet_explorer | 10 |
| microsoft | windows_server_2012 | all versions |
| microsoft | internet_explorer | 11 |
| microsoft | windows_10_1507 | all versions |
| microsoft | windows_10_1507 | all versions |
| microsoft | windows_10_1607 | all versions |
| microsoft | windows_10_1607 | all versions |
| microsoft | windows_10_1703 | all versions |
| microsoft | windows_10_1703 | all versions |
| microsoft | windows_10_1709 | all versions |
| microsoft | windows_10_1709 | all versions |
| microsoft | windows_10_1709 | all versions |
| microsoft | windows_10_1803 | all versions |
| microsoft | windows_10_1803 | all versions |
| microsoft | windows_10_1803 | all versions |
| microsoft | windows_10_1809 | all versions |
| microsoft | windows_10_1809 | all versions |
| microsoft | windows_10_1809 | all versions |
| microsoft | windows_7 | all versions |
| microsoft | windows_8.1 | all versions |
| microsoft | windows_rt_8.1 | all versions |
| microsoft | windows_server_2008 | r2 |
| microsoft | windows_server_2012 | r2 |
| microsoft | windows_server_2016 | all versions |
| microsoft | windows_server_2019 | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/106886
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0676
- http://www.securityfocus.com/bid/106886
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0676
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0676
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2019-0676