CVE-2016-0189: Microsoft Internet Explorer Memory Corruption Vulnerability
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0187.
Other sources
The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0189?
CVE-2016-0189 is rated as critical due to its potential for remote code execution.
How do I fix CVE-2016-0189?
To mitigate CVE-2016-0189, apply the security updates provided by Microsoft.
Which versions of Internet Explorer are affected by CVE-2016-0189?
CVE-2016-0189 affects Internet Explorer versions 9, 10, and 11.
What are the consequences of CVE-2016-0189 exploitation?
Exploitation of CVE-2016-0189 can lead to arbitrary code execution or memory corruption, resulting in a denial of service.
Are JScript and VBScript impacted by CVE-2016-0189?
Yes, both JScript version 5.8 and VBScript versions 5.7 and 5.8 are impacted by CVE-2016-0189.